- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
We would like to create FW rules to only authorize HTTP and HTTPS traffic (without decrypt HTTPS traffic) regardless of the port used (standard or not). Is-it something feasible without Application control license?
Thank you very much for your feedback,
Regards
Unlike traditional solutions then Check Point Application Control/URL Filtering do not rely on having the database locally.
They instead have very limited cache at the Appliance level but then rely on connecting from the Gateway to the Cloud to do the categorization.
So in order for AppCtrl/URL to work then it needs to be able to connect to the Check Point Cloud to do the categorization.
IPS can have an offfline update but not the AppCtrl/URL
Thank you for your help, I get from Checkpoint a trial license for testing purposes.
But after that I had an issue. I activated application control & url filtering blade and create a rule to match web browsing traffic (With Any as services). The rule is not matched except if I remove Web browsing application and use instead Any.
Do you how can I troubleshoot this? I didn't find any documentation about application control troubleshooting part.
ATRG for Application Control
Thank you very much,
Thanks to your sk links I think I found the issue explanation. Appi_status.C file show an empty value on variable
app_db_version () and I have this app_update_description :
"Update failed. Gateway can not access internet ('https://secureupdates.checkpoint.com/appi/v4_0_1/gw/Version'). Check connectivity and proxy settings
I didn't understand internet access was also needed on Security Gateway, A proxy was only configured on the management server.
Is there any other way to get application dabatase update without configuring internet access on the gateway ? For example retrieving update from management instead ?
Unlike traditional solutions then Check Point Application Control/URL Filtering do not rely on having the database locally.
They instead have very limited cache at the Appliance level but then rely on connecting from the Gateway to the Cloud to do the categorization.
So in order for AppCtrl/URL to work then it needs to be able to connect to the Check Point Cloud to do the categorization.
IPS can have an offfline update but not the AppCtrl/URL
Ok it's clear, thank you for your help
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 19 | |
| 11 | |
| 8 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY