Question for the group which I have always struggled with - if you have a choice on how to allow traffic to an internet service, is it better to use an Application (provided by Check Point) or a URL list (provided by the hosting site)?
An example: we have a few servers which need to access certain Microsoft functions. We can create a custom Application/Site and put the list of URLs and IP address provided by Microsoft and use this in the rule. Or, we could use an Application object (e.g. "Microsoft Services", provided I can figure out which one would be the best match) and use this in the rule. Is there a rule of thumb or guideline or best practice for these situations? How have you handled this?
Thanks,
Dave