Firewall: 1900/2000 Appliance running version R81.10 with Application Control and URL Filtering enabled, as well as HTTPS-inspection. Obligatory heads-up, I am not an expert (or even intermediate) when it comes to networking and checkpoint.
Hi there checkmates,
We're trying to configure a firewall for a highly-regulated, mostly closed environment (meaning only specific software and addresses may be accessed from the internal network). To this end, we try to regulate access mostly based on custom applications/sites and built-in updatable objects. However, we've found something that seems quite inconsistent; the exact same url that is both allowed and blocked in two separate instances.
We are allowing traffic to the source 'api\.github\.com/repos/hashicorp/packer-plugin-vsphere/git/matching-refs/tags.*' (defined as a regex), but this is what we observed below:

Both these instances happen near-simultaneously. The rules were not changed in that short time (we've checked). We did see that both instances went to a different host (140.82.121.3 and ".6 respectively), but all hosts are allowed in this rule as long as the url matches, so this should not make a difference. Furthermore, in the Policy menu it shows both as blocked by the cleanup rule, even though one is still allowed. Does anyone here have an inkling as to what is going on here?