- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
We want to set up geo protection for certain websites. However, there many sites behind one IP using SNI behind one IP address on haproxy. Is this possible to protect one or two URLs (name) with a geo policy? I know SNI is supported with https inspection. Or would every project hosted behind that one IP have to be on the policy?
I assume this is possible since:
SNI doesn't require HTTPS Inspection, FYI.
I assume this is possible since:
SNI doesn't require HTTPS Inspection, FYI.
rule #12 using a geography as source (blocking Russia for example) and a custom application as destination
rule #13 allows the IP. Sources from Russia wouldn't make it to rule #13 they would be blocked on #12.
Sounds good.
Hey Dan,
Can you send screenshot?
Andy
Thanks, the application/site object works great in the access policy. Now, moving on to the threat prevention exception policy.
La Question du jour: Can a custom application/site object exist in the threat prevention Exceptions policy sort of acting as a destination site? I was focused adding a site object to the protected scope column (can't do it), but there is also the protections/site/file/blade column that I've only been using to add protection exceptions. IOW, when making an exception for an IP (and that IP can represent 100 sites) We just need an IPS exception for 1 of the 100 sites. Currently, the protected scope doesn't support application/site objects. However, I can and did simply add the site object to the column with the list of IPS protections the exception is for. IOW, I have 10 IPS protections and a site all in the same column. I mean the column does say it's for Protections/site/file/blade. It just seems very unusual to have that mix of protections and a specific destination (site object/URLs) in the same column. Thinking... that might just work.
Yea, probably best idea Dan.
Let us know one way or the other.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 28 | |
| 20 | |
| 15 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY