- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi everyone,
I'm setting up DLP Blade for POC at the customer (OpenServer - R81.20) but seems like it's not working correctly.
Here is the Policy:
So when the client behind the gateway tries to upload files:
Some sites working get log and alert email: Gmail, LinkedIn, Onedrive,...
Some sites are not working (no DLP log, just normal traffic log): Google Drive, Facebook, Telegram,...
Other Blade I set the default configuration so I don't think it's a conflict.
Have I configured something wrong?
Please help me..
Thank you so much.
Are you doing HTTPS inspection on this traffic?
The logs shows UDP 443 that is encryped.
Https inspection already done:
I did install cert on client, in GG Drive website, that show https inspection cert:
That is good! UDP 443 cannot be inspected and would be best to block. As others already posted. I can see you have done this now.
Further info about this is listed here: https://support.checkpoint.com/results/sk/sk111754
Could it maybe be a character / language issue? If I see your screenshots 🙂
Are you blocking QUIC traffic in your environment?
I'm testing with allow *any all, and block only quic UDP-443 in FW Layer, but DLP on GG Drive, Facebook,... still not working:
Does zdebug show anything for the IP site resolves to?
fw ctz zdebug + drop | grep x.x.x.x
Just put the ip address after grep
Andy
When i'm trying upload to drive:
run command I saw it's not dropping anything:
As Chris said, QUIC can definitely be the issue.
Hi the_rock, do we support to do the DLP Policy for native applications such as Google Driver, Telegram, Dropbox...?
You may want to ask internally as well, but Im pretty sure you do support it.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 19 | |
| 11 | |
| 8 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY