- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We have a R80.10 cluster which has Firewall, IPS, Anti-Virus and Anti-Bot Blades in place and it is being used as a parent proxy. When the IPS/AV detect a virus signature (in this case the test Eicar virus) it drops the connection to the child proxy, however if the Anti-bot detects an issue which is classed as reputation it is redirected to the UserCheck error pages. How do we set up the firewall to redirect all the "proxying" requests to UserCheck when there is a Threat Prevention issue ?
Is the firewall an explicit proxy in this case?
Because if so, we may not be able to redirect the traffic to a UserCheck page.
See: How to configure Check Point Security Gateway as HTTP/HTTPS Proxy
Otherwise, a diagram of how the proxies are configured (related to users and Internet) would be helpful.
Yes it is being used as an explicit proxy.
The browsers are setup to use a proxy on the internal network which is configured to use the firewall as a parent proxy.
Not 100% as we don't manage the internal proxy but believe it is using a proxy.pac file.
What I suspect is happening is that AV/IPS cannot see there's something to block until well after the connection is established (almost over in the case of AV).
As we are past the point of being able to inject any sort of redirect at that point, it's not possible for us to inject a UserCheck page.
As a result, we just drop the connection, which I assume the client proxy then picks up as an issue and displays its own page.
With an Anti-bot reputation, we can check that before a real connection is established and thus display a UserCheck page to the user.
The comment I was going to make about proxy.pac file is to make sure that connections redirected to the gateway itself are not sent through a proxy, which may already be happening.
Thanks for looking at this and answering the question, appreciated.
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY