<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Enable (Inbound/Outbound) HTTPS inspection on AWS Auto Scaling / Azure VMSS / GCP MIG in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-Enable-Inbound-Outbound-HTTPS-inspection-on-AWS-Auto/m-p/241076#M5225</link>
    <description>&lt;P&gt;Greetings from Colombia Shay,&lt;/P&gt;&lt;P&gt;We are presenting a problem with a client in azure and vmss, when we scale new firewall the ssl inbound inspection stops working and also we stop seeing inspection logs, I wonder if it is necessary to do some extra configuration when doing https inspection inbound with vmss.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2025 03:00:25 GMT</pubDate>
    <dc:creator>Naguinix</dc:creator>
    <dc:date>2025-02-13T03:00:25Z</dc:date>
    <item>
      <title>How to Enable (Inbound/Outbound) HTTPS inspection on AWS Auto Scaling / Azure VMSS / GCP MIG</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-Enable-Inbound-Outbound-HTTPS-inspection-on-AWS-Auto/m-p/152886#M1084</link>
      <description>&lt;P&gt;If you want to enable SSL inspection on exiting scale set or to a new scale set, you might need to make an additional configuration step.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shay_Levin_0-1657713575633.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17169iE7FFADD66A74AD41/image-size/large?v=v2&amp;amp;px=999" role="button" title="Shay_Levin_0-1657713575633.png" alt="Shay_Levin_0-1657713575633.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Once you enable https inspection on the CME template you will get a message that HTTPs need to be configured in SmartConsole.&lt;/P&gt;
&lt;P&gt;So, this is only true if you want to inspect outgoing traffic and you have not create an outbound certificate on the management before.&lt;/P&gt;
&lt;P&gt;The reason for that is that you have to create an outgoing certificate first on the Check Point management in order to inspect outgoing traffic.&lt;/P&gt;
&lt;P&gt;So if you have already created outbound certificate on one of the managed gateways on a management that is going to manage the scale set , you won’t need to do anything , the SSL inspection would work on the Scale Set as well.&lt;/P&gt;
&lt;P&gt;And it’s doesn’t important on which managed gateway you create the certificate in the past, it’s also doesn’t matter if the gateway still exist on the management. As&amp;nbsp;long has you did it once in the past , your Scale set will use the same certificate that exist on the management.&lt;/P&gt;
&lt;P&gt;So, on the example above I have set https on the CME template for a new Scale Set deployment and the Check Point management is completely new.&lt;/P&gt;
&lt;P&gt;If you will check the HTTPS configuration on one of the ScaleSet gateways&lt;/P&gt;
&lt;P&gt;You will notice that https is enabled.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shay_Levin_1-1657713575639.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17170i2C3027AFE7D5A368/image-size/large?v=v2&amp;amp;px=999" role="button" title="Shay_Levin_1-1657713575639.png" alt="Shay_Levin_1-1657713575639.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;For inbound ssl inspection it’s good enough but for outbound inspection you will need to create the outbound certificate.&lt;/P&gt;
&lt;P&gt;Once you create the outbound certificate once,&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shay_Levin_2-1657713575642.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17171i2B929F45B8FB22E9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Shay_Levin_2-1657713575642.png" alt="Shay_Levin_2-1657713575642.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;All the existing Scale Set gateways and any new Scale Set gateways will use the same outbound certificate.&lt;/P&gt;
&lt;P&gt;So just, remember that you need to do this procedure only one time and you are set.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will need of course to make additional configuration describe bellow, but it’s not unique for scale set, those are general https inspection configuration steps.&lt;/P&gt;
&lt;P&gt;For outbound inspection, you will need of course also to deploy the outbound certificate to the instances that are going to be inspected and set the SSL inspection policy.&lt;/P&gt;
&lt;P&gt;For inbound inspection, you will need to import the private key of the site you want to protected to the Check Point management and create an SSL inspection Policy.&lt;/P&gt;
&lt;P&gt;For more information about HTTPS Inspection read&amp;nbsp; &lt;SPAN&gt;sk108202 -&lt;/SPAN&gt; Best Practices - HTTPS Inspection &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108202&amp;amp;partition=Basic&amp;amp;product=HTTPS" target="_self"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 12:14:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-Enable-Inbound-Outbound-HTTPS-inspection-on-AWS-Auto/m-p/152886#M1084</guid>
      <dc:creator>Shay_Levin</dc:creator>
      <dc:date>2022-07-13T12:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to Enable (Inbound/Outbound) HTTPS inspection on AWS Auto Scaling / Azure VMSS / GCP MIG</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-Enable-Inbound-Outbound-HTTPS-inspection-on-AWS-Auto/m-p/241076#M5225</link>
      <description>&lt;P&gt;Greetings from Colombia Shay,&lt;/P&gt;&lt;P&gt;We are presenting a problem with a client in azure and vmss, when we scale new firewall the ssl inbound inspection stops working and also we stop seeing inspection logs, I wonder if it is necessary to do some extra configuration when doing https inspection inbound with vmss.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 03:00:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-Enable-Inbound-Outbound-HTTPS-inspection-on-AWS-Auto/m-p/241076#M5225</guid>
      <dc:creator>Naguinix</dc:creator>
      <dc:date>2025-02-13T03:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to Enable (Inbound/Outbound) HTTPS inspection on AWS Auto Scaling / Azure VMSS / GCP MIG</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-Enable-Inbound-Outbound-HTTPS-inspection-on-AWS-Auto/m-p/241091#M5226</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;if you enable HTTPSi from CME and you already have the certificate and policies then it should work, no other configuration is needed.&lt;/P&gt;
&lt;P&gt;Just wait for the instance to be created and policy installed.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 05:54:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-Enable-Inbound-Outbound-HTTPS-inspection-on-AWS-Auto/m-p/241091#M5226</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2025-02-13T05:54:36Z</dc:date>
    </item>
  </channel>
</rss>

