Show
1 - 10 of 36,011 discussions
Sorted by:
Hi everyone, I’m trying to block WhatsApp on my network using Check Point. I have applied the relevant policies and added the WhatsApp application categories/tags within Application Control. The pa...
-
Hi Don,
:path need to be a complete URL of a directory that contains in it urls.txt and Vers...
- Fair enough! CP/Community authority/legend/evangelist @PhoneBoy to the rescue. Andy
- Thanks 🙂
- Hey Steve, All I did was add *whatsapp* and do NOT check regular expressions, thats it. Rule look...
- Thanks Larry 😉 Is that related to the new R82 JHFA 41 feature or a custom App with just *w...
- Thanks. We need a WhatsApp Updatable Object 🙂 Just been looking at the new feature in th...
- I flagged R&D on this.
- Good day Don, Im super curious to see how this works out for you, in regards to whatsapp. Please ...
- @Don_Paterson There you go : - ). Btw, happy to do remote and help if you guys allow that. ...
2025-09-15
05:32 PM
60
Replies
6533
Views
Hi CheckMates!
This message is relevant only for customers using VPN Site-to-Site and Remote Access VPN Security Gateways using certificates issued by DigiCert External CA.
No action is required ...
-
UPDATE - DigiCert Certificate Expiration Mitigated
Hi CheckMates
&n...
- ok, thanks
- Hi We were just alerted to this which requires action in the next week. Looking at the SK it says...
- The mentioned SK is still a work in progress. All required hotfixes and also a script to check whet...
- Once everything is in place, we will create a post and merge all related discussions
- Thanks for that Val.
- I contacted Digicert support, and this affects all Digicert brands, which include GeoTrust and Rapi...
- While there may be some additional updates to the SK, including the script that tests whether a hot...
- Thanks for that @Alex_Lewis
Since the general availability of Windows 11 24H2, we're noticing around 50% of Windows machines updated to 24H2 are failing to connect with the Remote Access VPN. I noticed that with the release of...
-
Maybe try newest E89 version.
Andy
-
This was fixed. The fix is included in: Enterprise Endpoint Security E88.62 (E88.61 Hotfix) ...
-
If you are still having issue with Windows 11 24h2, Please see SK182749, you could wither modify th...
-
Assuming this is the true solution to the problem, I would expect us to set route_conflict_resoluti...
-
Please, can you try to set the "route_conflict_resolution_method" parameter to "modify" in trac_cli...
- Hi, I guess no update? It's really becoming a pain, and workarounds (different laptops running diff...
- Not heard an updated ETA yet.
- Should also be corrected in E88.62 (recent) as well E88.70 (newest) on client side out of the box s...
The following one-liner identifies all rules with a hit count of 0 entries. Depending on your environment, you may need to adjust the policy name to ensure the command runs against the correct config...
-
@Bob_Zimmerman, @the_rock, @PhoneBoy I quickly created the SmartConsole extensio...
-
Hi, Thank you for your feedback. We found out that the SmartConsole release didn't include the h...
- @Bob_Zimmerman Thanks for the good tip with the date of the old rules! Technically, your...
- 13000 rules?! My only comment = no comment :=)
- That is SUPERB. Just ran it in my lab and it showed exact rules with 0 hits...amazing. Andy [...
- Back in good old times (before R8x), there was SmartDashboard feature build in by default where you...
- Important notes: the one-liner above to find rules with no hits does not consider rules inside a se...
- Wait a second...what caught my eye in your screenshot is why layer shows automatic...isnt this ONLY...
- It still bugs me why that feature was removed...it was so useful.
I’ve noticed that in a VSX environment the virtual switches don’t seem to achieve very high packet throughput. In practice, I can’t get more than around 4–5 Gbps over a wrp interface. When I connec...
-
There should be no performance degradation. The issue is specific to UPPACK and has been identified...
-
@genisis__ @HeikoAnkenbrand Answering all questions in one post - The virtua...
- We also have a VSwitch environment as a large university hospital. It's very convenient that we don...
- What version/JHF level?
- I've never really dug into the networking guts of VSX, but the fact you are topping out at 4–5...
- @PhoneBoy We use R81.20 JHF 105.
- @Timothy_Hall First of all, thank you all for sharing your insights. I had already tested most of...
- This post describes a similar experience with inter-VS traffic utilizing virtual switches and ...
- I've seen similar throughput observations with VSwitches. When switching into the VSW at the ...
Hi, While reviewing the SIC certificates on my SMS (cp_mgmt), I noticed there are multiple duplicates. Currently I can see 4 certificates: CN=cp_mgmt (3 times) CN=cp_mgmt_mysms My goal is t...
-
I did this before and tunnels are fine, BUT, make sure to backup all those files and do it in maint...
-
@the_rock I performed the activity following the steps described at the beginning of this ...
- @jennyado Sorry...I read your post CAREFULLY again and those steps make perfect sense to me. H...
- All good, questions are free lol Can you give an example, I can check the lab? Gotta jump on harm...
- While reviewing SIC certificates on my gateways using: cat /pfrm2.0/config1/fw1/registry/HKLM_re...
- From my lab and dont worry about ones that say john smith and ica mgmt, that was when I was testing...
- Also Jenn, if you are ever in doubt, just see what this line says on your side...this HAS TO MATCH ...
- Thanks again for your previous feedback—it was really helpful. I have another question regarding th...
- Here’s an example from my environment for reference: SMS certificate: CN = cp_mgmt O = Examp...
Can someone explain the inconsistency with sk177714 (in-place upgrade of an R81.20 SmartCenter in CloudGuard) versus what is actually happening on the server?
Sep 25 18:33:03 2025 mercury xpan...
-
Just to wrap this up, and let "Future Me" and "Future You" know, this "aio" package worked well to ...
- Last time I did this, I just ended up doing it from web UI, like regular Gaia and worked fine. An...
- Sadly, the package isn't being added to the repository, so it's not selectable. I even tried ...
- Just in case: You would run 1 or 2: 1. clish installer import cloud aio_Check_Point_R8...
- I will try that in the lab, but I never recall seeing sign = after word package. Andy
- I agree, boo : - ( Anywho, here is my ?...what do you see in updates tab at the bottom left of we...
- Oh! Fair enough, my fault for not clicking the link, I did miss that; I didn't see there was ...
- I've found CPUSE doesn't like to download packages with a tar extension. You probably just need to ...
- Hey Duane, Did you figure this out? Andy
Hello, For a project that I am working on, where the Check Point VM can be destroyed and brought back up, I am trying to automatically assign the Management interface via DHCP client. This works fin...
-
I did not forget about the topic, I've just been slow to work on it... and I think I now have somet...
- Actually, even when trying to fix it manually, by changing the IP address, it doesn't work: cpfw&g...
- Thank you for your reply. I was able to connect to the SmartConsole and manually update the IP add...
- Your management server should not have a DHCP address in the first place. SIC with the security GWs...
- This is a great idea, I forgot about this command, I saw it a little while ago. It does work pretty...
- Maybe this? clish> add interface eth0 alias <dhcp-ip>/24 clish> save config
- It's only at the creation of the VM that I want to use DHCP to assign the IP address, once the VM i...
- I would just use cloud-init to handle the first-time config when the VM is built. I did something s...
- What exactly are you building? You mentioned Vagrant. Is this about reproducible lab environments? ...
2 weeks ago
24
Replies
1549
Views
Hello Checkmates, this is my first time creating a post here. 🙂 Also, I'm fairly new to CheckPoint firewalls. I'm seeing what I consider slow VPN tunnel speed/throughput between sites.&...
-
First off, WELCOME :). Secondly, totally valid points. I would refer you to below sk, as it would c...
- Thank you! Yes, I'm willing to take a bit more risk since we only deal with file/print and no...
- As an addition: - enabled TP blades maketraffic slower - try to open more than one connection a...
- Thank you! 🙂 I'm seeing the encryption types might be the issue for me. looking ...
- Which encryption algorithms are used? Is MSS clamping configured? How is the test being run, ar...
- Thanks, I'm not familiar on how to do this on checkpoint. Can you provide guidance on how to ...
- Technically, it might interrupt the tunnel for few minutes, since it needs policy push and probably...
- Hi Chris, Thank you for the quick response. 1. see attached screenshot of the VPN community...
- Here is one IMPORTANT thing to remember...so, faster algorithms will NOT be as secure as slower one...
Hi, i have a quantum 1600 device which i need to authenticate against the new Windows Server 2025 AD Server. But i can only enter an IP Address and so is not possible to successfully connect my appl...
-
@G_W_Albrecht @LM-Rafael @Tom_Hinoue Hi Guys,
Quick summary of the is...
- @G_W_Albrecht Hi Everyone, We currently have an active workaround in place, but we still ...
- @itayravenna , @Amir_Ayalon any news on fixing the WIN 25 server integration?
- Hi @G_W_Albrecht We are still working on it.
- @itayravenna , any news ?
- Two weeks later: Any fix or SK available ?
- Is an SK available ?
- I got a different answer regarding the recommended support ver.. in my SR, RnD advised to use Windo...
2025-01-08
01:53 PM
44
Replies
6319
Views