- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hello All,
I have blocked ChatGPT and Google Gemini, using their respective apps in App&URL policy. the access to these two is blocked.
but i cannot block Microsoft copilot uisng the "Microsoft Copilot" app.
I have also tried creating a custom app, using chat.bing.com which is forwarded to bing.com/chat, without any luck. Customer do not want to get blocked for bing.com, but only the chat/AI should be blocked.
Also tried blocking bing.com/chat (chat.bing.com gets forwarded to this) and used Regex as well, but for some reason, Microsoft copilot is not getting blocked.
even tried to manually override the bing.com/chat category.
SMS and Gateways on R81.10 JHA take 156.
Any help will be much appreciated.
Thanks
Have you tried the "Artificial Intelligence" category or is there a reason that you're attempting to be more specific?
Yes i did try that first. it blocks lots of internal apps as well that are required. so decided to block only the specific ones.
Funny thing is Microsoft copilot was not blocked even when using the whole AI category.
You can add the specific application to the rule:
I see. I will ask relevant teams to look at this.
Thanks a lot.
If you haven't already, I suggest opening a TAC case: https://help.checkpoint.com
I did exactly what @Tal_Paz-Fridman suggested, worked fine. I also made sure its inspected by https policy and verified copilot.microsoft.com is blocked as well.
Andy
That could be the thing. we have not enabled https inspection, instead using SNI, and its working for other two Apps. not for MS Copilot though.
due to the URL redirection, I guess SNI is not working as expected.
@PhoneBoy what do you think, should raise a TAC case?
That could be the issue, you most likely need ssl inspection turned on, not sure how it can work otherwise.
Andy
Also, check out this post from 2021. I know that was before R81.20, but it has lots of GREAT responses.
Andy
That was a good read. Thanks a lot.
To block a specific URL (e.g. bing.com/chat), you definitely will need HTTPS Inspection.
Possible that is required for the App Control signature to work.
Yes i understand. Thanks a lot.
100% you would need ssl inspection enabled for the app control to fully function, for sure.
Let me try explain it in simple terms, hope it will make sense, but if not, let me know...so with ssl inspection on, fw will act as MITM (man in the middle), intercepting requests between client/server. Without it, yes, you can block pages, BUT, block page will never show up, as there would be nothing for the firewall to inspect/intercept.
Same goes for any app you wish to block.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
25 | |
13 | |
9 | |
9 | |
7 | |
7 | |
6 | |
6 | |
5 | |
4 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY