Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
the_rock
Legend
Legend
Jump to solution

Content awareness problem

Hey guys,

Wondering if anyone may have some experience with this blade, more specifically, getting files to be blocked when its enabled 🙂

So, essentially, we got this working few years ago, but customer decided back then not to use the blade and they would like to do it at this point. Issue is literally the same like the post I had back in the day.

https://community.checkpoint.com/t5/Security-Gateways/Content-awareness-issue/m-p/156026/emcs_t/S2h8...

R81.20 jumbo 98

We did exact same steps esc. engineer gave us and no luck, we dont even see any logs for the blade at all when exe files is downloaded.

Before doing any debugs from below, wondering if anyone may have any other ideas/suggestions. I will also open TAC case to see what they say.

https://support.checkpoint.com/results/sk/sk119715

Thanks as always and happy weekend 🙂

Andy

0 Kudos
30 Replies
the_rock
Legend
Legend

Hey everyone,

Just to update, we had a call with T3 guy from Dallas, awesome support, customer was very happy. We ended up using AV blade to block msi and exe files and worked just fine. What we had to do is modify TP policy to block correct files, but then we had issue with windows update, so TAC will check on that further, since it was failing even in my lab.

Thanks everyone for your help! They key is indeed to disable bypass rule in inspection policy and have same rule in url layer.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events