CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-08
Member
 
Join Date: 2007-01-30
Location: Abudhabi
Posts: 48
Rep Power: 0
sridharraj80 has an average reputation (10+)
Default Block HTTPS traffic for particular group

Hi ,

Can anyone help out how to block https traffic for a particular group alone in R60 .

Thanks in advance.

Sridhar
Reply With Quote
  #2 (permalink)  
Old 2007-02-08
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Block HTTPS traffic for particular group

How do you define that group?

If it's a subnet, group or range of IPs, you can just create a rule before the allow like this:
Group - Any - HTTPS - Drop

If you want to block users, then you will need to have them authenticated on FW-1 so you can have a more granular access control.

I do however prefer to deny anything by default and always work with allow rules, so I would probably try to do this by giving HTTPS to another group, rather than blocking this one.
Reply With Quote
  #3 (permalink)  
Old 2007-02-08
Member
 
Join Date: 2007-01-30
Location: Abudhabi
Posts: 48
Rep Power: 0
sridharraj80 has an average reputation (10+)
Default Re: Block HTTPS traffic for particular group

Hi ,

Thanks for the reply .. This is a particular Subnet based group. And i wanna block https://gmail.com, https://mail.yahoo.com kind of sites for accessing for those subnet..

Will URI filtering be the best one for this. Please suggest on this.

sri
Reply With Quote
  #4 (permalink)  
Old 2007-02-08
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Block HTTPS traffic for particular group

If you wanted to block HTTP sites you could create URI resources, group them and then block those.
For example Gmail could be defined like *.gmail.com, with * in path too.

Then you would create a rule like this:
Subnet - Any - HTTP->Resource group - Drop

I just checked on the GUI and it seems to allow you to use HTTPS too, so you can try that. It's not a very scalable process though, most ppl get proper URL filtering.
Reply With Quote
  #5 (permalink)  
Old 2007-02-12
Member
 
Join Date: 2007-01-30
Location: Abudhabi
Posts: 48
Rep Power: 0
sridharraj80 has an average reputation (10+)
Default Re: Block HTTPS traffic for particular group

Hi Thanks for the reply,

I have configured and tested it sucessfully.. Thanks for the reply again.. Now again my company wants me to customize block page (error page) .

How do i customize this ? Please help me out in solving this..

thanks in advance.
Reply With Quote
  #6 (permalink)  
Old 2007-02-13
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 466
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Block HTTPS traffic for particular group

Quote:
Originally Posted by sridharraj80 View Post
Hi Thanks for the reply,

I have configured and tested it sucessfully.. Thanks for the reply again.. Now again my company wants me to customize block page (error page) .

How do i customize this ? Please help me out in solving this..

thanks in advance.
you have the tab on uri resource object called action, where you can enter replacement/redirect url. You could point it to error html page that resided on a webserver you have.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 23:19.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0