- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi everyone,
I'm setting up DLP Blade for POC at the customer (OpenServer - R81.20) but seems like it's not working correctly.
Here is the Policy:
So when the client behind the gateway tries to upload files:
Some sites working get log and alert email: Gmail, LinkedIn, Onedrive,...
Some sites are not working (no DLP log, just normal traffic log): Google Drive, Facebook, Telegram,...
Other Blade I set the default configuration so I don't think it's a conflict.
Have I configured something wrong?
Please help me..
Thank you so much.
Are you doing HTTPS inspection on this traffic?
The logs shows UDP 443 that is encryped.
Https inspection already done:
I did install cert on client, in GG Drive website, that show https inspection cert:
That is good! UDP 443 cannot be inspected and would be best to block. As others already posted. I can see you have done this now.
Further info about this is listed here: https://support.checkpoint.com/results/sk/sk111754
Could it maybe be a character / language issue? If I see your screenshots 🙂
Are you blocking QUIC traffic in your environment?
I'm testing with allow *any all, and block only quic UDP-443 in FW Layer, but DLP on GG Drive, Facebook,... still not working:
Does zdebug show anything for the IP site resolves to?
fw ctz zdebug + drop | grep x.x.x.x
Just put the ip address after grep
Andy
When i'm trying upload to drive:
run command I saw it's not dropping anything:
As Chris said, QUIC can definitely be the issue.
Hi the_rock, do we support to do the DLP Policy for native applications such as Google Driver, Telegram, Dropbox...?
You may want to ask internally as well, but Im pretty sure you do support it.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 10 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY