Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JPR
Collaborator

Zoom and Custom Application/Site

I got two questions I hope some of you can help me with.

1)

I have a rule in my rulebase that looks like this:

zoom.png

The content of the Custom Application Site is this:

zoom1.png

I have a rule further down that blocks various categories. When I go to https://zoom.com it hits the rule above and I get to the site. When I go to https://zoom.us it doesn't hit the rule above, but continues and gets blocked by the rule that block various categories. Do any of you have any idea as to why that is?

2)

Zoom.us gets blocked because it falls into the category of "Web Confenrencing":

blockzoom.jpg

The funny thing is, though, we don't block for that:

blockcat.png

Do any of you have an idea to why it gets blocked anyway?

Thanks!

0 Kudos
7 Replies
Tal_Paz-Fridman
Employee
Employee

Have you tried using the predefined Zoom applications?

 

Zoom Application.png

 

Zoom Applications.png

JPR
Collaborator

Sorry, I can see I needed to add a bit more context.

The thing is, that it is an inline rule:

zoominlinwe.png

So we allow conncetions to zoom.com and zoom.us unless it is one of these URLS:

zoomdeny.png

We don't allow people to join Zoom meetings from our internal environment, but they need to be able to schedule meetings and so on.

0 Kudos
AkosBakos
Leader Leader
Leader

Hi @JPR 

The HTTPs Inspection is enabled on the firewall?

 

2025-02-19 13_14_28-Zoom and Custom Application_Site - Check Point CheckMates.png

https://support.checkpoint.com/results/sk/sk106623

Akos

----------------
\m/_(>_<)_\m/
0 Kudos
PhoneBoy
Admin
Admin

That’s weird because zoom.us shows up as Computers/Internet when I look it up:

IMG_2893.jpeg

Do the logs explicitly say this is the rule that is blocking the traffic?
And are you using HTTPS Inspection because you can’t block on a specific HTTPS URL without it.

JPR
Collaborator

I've tried to modify my rule(s) the way Akos suggested and it worked yesterday, but this morning zoom.us was again being blocked:

zoomblock.jpg

HTTPS Inspection in enabled and it gets inspected, however, I no longer see any categorization in the actual log:

httpsi.jpg

And I experience the same for cran.r-project.org that gets categorized as Computer/Internet (which we don't block), however, it hits our blocking of categories rule. And again there's no category in the log in SmarteConsole.

The above was a mistake. cran.r-project.org is categorized as Software Downloads and that we are blocking (r-project.org is categorized as Computers/Internet and works); my bad...

I still don't see any categories in the Smart Console logs. Is that an issue, though?

Any ideas? 😕

0 Kudos
PhoneBoy
Admin
Admin

I suggest involving TAC here.

the_rock
Legend
Legend

What I always do in my lab is create custom category like you did, but simply add *zoom*, thats it.

Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events