- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi Guys,
Currently URL filtering blade is not enabled, and we would like to enabled it. To minimize the impact, we are planning to apply URL filtering only to 1 generic rule.
On a different firewalls we can enable this 'url filtering' profile per rule basis, How to do this on Checkpoint?
Is it possible to apply URL filtering only for 1 rule? and can we achieve this with inline layer?
Thanks!
Please have a look at Creating Application Control and URL Filtering Rules, sk65124 - URL Filtering Blade FAQ and sk92743: ATRG: URL Filtering.
The use of either inline or ordered layers may be helpful here and is covered in the admin guides:
Hi Chris,
Thanks for the response, I have read the guide and looks like inline layer may achieve my requirement. I have a couple of questions,
Important - Always add an explicit Cleanup Rule at the end of each Inline Layer, and make sure that its Action is the same as the Action of the Implicit Cleanup Rule. |
No. | Type | Name | Source | Destination | VPN | Services & Applications | Content | Action |
1 | 192.168.1.0 | 192.168.1.0/24 | Any | Any | http | Any | Accept | |
2 | 10.0.0.0/16 | 10.0.0.0/16 | Any | Any | http | Any | Accept | |
2.1 | Inline Allow Whitelist URL | Any | Any | Any | [whitelisted-url] - custom application site object | Any | Accept | |
2.2 | Inline Cleanup Rule | Any | Any | Any | Any | Any | Drop | |
3 | Cleanup Rule | Any | Any | Any | Any | Any | Drop |
Thanks
I am going to reply again, for some reason my previous reply is missing.
hi @Chris_Atkinson thank you for your response, I've look the the admin guide and have a couple of queries below
below is the snippet from admin guide,
Important - Always add an explicit Cleanup Rule at the end of each Inline Layer, and make sure that its Action is the same as the Action of the Implicit Cleanup Rule. |
Inline layers are a great way to test this.
What your implicit cleanup rule for the inline layer should be in this case depends on your goal.
Just know that if it hits an accept rule in the inline layer, the next ordered layer will be evaluated (if there is one).
Likewise, a drop in the inline layer (even if the implicit drop rule) means the connection will be dropped.
Hi @PhoneBoy
Thank you for your valuable input.
last question that i have in mind about below
'Just know that if it hits an accept rule in the inline layer, the next ordered layer will be evaluated (if there is one).
What happen if those are the same, for example I have 2 ordered layer, 1st is firewall and 2nd is application/URL.
If I create application/URL inline layer on my firewall blade and it hits an accept rule in that inline layer.
will it still be evaluated against the application/URL on the ordered layer?
Thanks!
If you use ordered layers, the packet must hit an accept rule in each layer, regardless of what blades are active in each layer.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY