- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- appl/urlf AWS S3 not recognized
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
appl/urlf AWS S3 not recognized
Hi there,
R80.30 JHF111 with inspection enabled. I build the policy with only AWS S3 application allowed. Everything else is dropped.
In the logs I see that when connection goes to s3.amazonaws.com, it is recognized correctly, but when connection goes to s3.eu-central-1.amazonaws.com for example, it is now no longer S3 app, but generic computers/internet category.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Screenshot?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
the rule is very simple:
source: server, destination:internet, services&app - amazon S3. Next rule - drop any.
As a workaround I added custom app with urls I mentioned in previous post which are not automatically recognized as Amazon S3, however I am interested what attributes second link is missing that prevents tagging it as AWS S3 app. I would guess that checkpoint is not making decision about app only by url.
s3.amazonaws.com
s3.eu-central-1.amazonaws.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Might be worth a TAC case.
