Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
NilsKS
Participant

Limit outbound HTTPS on servers using ADSync / Azure ARC / Akamai

Jump to solution

Hi,

Check Point FW-1 R81.10.

I am in the process of implementing application rules to control/limit outbound http/https. Have this up and running for most Windows servers, but I am struggling with servers monitored by Azure ARC and servers running ADsync.

I have allowed the following services / application in the application rulebase:

cp.PNG

I still see lots of HTTP/HTTPS traffic to Microsoft Azure IP-addresses, but I am not able to find any (dymnamic) objects that includes Azure services /Azure ARC, ADsync).

Are there any Check Point objects that includes the Microsoft Azure IP addresses used for these services?? 

The same goes for Akamai HTTPS services. How to whitelist those??

 

Nils

 

 

0 Kudos
1 Solution

Accepted Solutions
Ilya_Yusupov
Employee
Employee

Hi,

 

Updating the thread, we saw 2 issues:

 

1. There is a known issue of some occasions that the package will not get updates and we have a fix that is not yet released in the Jumbo, should be in the future JHF release.

2. UI issue, where we tried to add object via right click add new items, in such flow most of the time the picker of updatable objects will not be opened, a bug that we will take it with RnD to solve.

 

Thank you very much for your feedback and time @NilsKS .

View solution in original post

4 Replies
Ilya_Yusupov
Employee
Employee

Hi @NilsKS ,

 

We do have updatable objects that address your requirement, did you tried it?

Please let me know if it's indeed answer your question or you are looking for something else.

 

Thanks,

Ilya 

0 Kudos
NilsKS
Participant

Hi Ilya,

This is the complete list of updatable objects on my firewall:

 

cp.PNG

I was looking for an application / service to allow these services with source:Internet, but I guess the correct thing to do is to use the above Windows / Microsoft updatable objects as source?

Thanks!

Best,

Nils

 

0 Kudos
Ilya_Yusupov
Employee
Employee

Hi @NilsKS,

 

i will take it with you offline as the list is not completed so i'm trying to understand what's went wrong there.

 

Thanks,

Ilya 

0 Kudos
Ilya_Yusupov
Employee
Employee

Hi,

 

Updating the thread, we saw 2 issues:

 

1. There is a known issue of some occasions that the package will not get updates and we have a fix that is not yet released in the Jumbo, should be in the future JHF release.

2. UI issue, where we tried to add object via right click add new items, in such flow most of the time the picker of updatable objects will not be opened, a bug that we will take it with RnD to solve.

 

Thank you very much for your feedback and time @NilsKS .