<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: err_ssl_protocol_error on a website in Browse</title>
    <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255698#M124</link>
    <description>&lt;P&gt;It's also used as part of Verified SNI.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Aug 2025 21:39:31 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-08-21T21:39:31Z</dc:date>
    <item>
      <title>err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255670#M120</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;A user needs to access a site which has a revoked certificate.&lt;/P&gt;&lt;P&gt;I accept to access on it, he does not need to authenticate or add any sensitive datas on it.&lt;/P&gt;&lt;P&gt;HTTPS inspection is not&amp;nbsp; activate, but url filtering yes and it shows as Detect the revoked certificate&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPS and antivirus blades are activated as well.&lt;/P&gt;&lt;P&gt;The same pc connected to a different Internet connection can surf on it.&lt;/P&gt;&lt;P&gt;Categorizsed HTTPS website is activated as well, on general properties.&lt;/P&gt;&lt;P&gt;How can I grant user access to this site?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 16:52:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255670#M120</guid>
      <dc:creator>Ilovecheckpoint</dc:creator>
      <dc:date>2025-08-21T16:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255693#M121</link>
      <description>&lt;P&gt;You posted this question in Harmony Browse space, yet you're asking this as if this is going through a gateway.&lt;BR /&gt;Confirm the product and versions/JHF in use.&lt;/P&gt;
&lt;P&gt;In any case, by default, we validate the certificate ourselves and deny access if the certificate is revoked.&lt;BR /&gt;This can be changed.&lt;BR /&gt;In R82, this can be done in SmartConsole:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31280i4599A3DD5AB54E77/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In R81.20 and earlier, it must be done in SmartDashboard:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31281i6467727BACFA8A24/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In either case, it requires publishing and installing the Access Policy to take effect.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 20:05:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255693#M121</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-21T20:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255695#M122</link>
      <description>&lt;P&gt;Do you have screenshot of it?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 21:03:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255695#M122</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-21T21:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255696#M123</link>
      <description>&lt;P&gt;I think that server certificate setting is only applicable though if they have https inspection enabled?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 21:09:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255696#M123</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-21T21:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255698#M124</link>
      <description>&lt;P&gt;It's also used as part of Verified SNI.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 21:39:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/255698#M124</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-21T21:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256150#M125</link>
      <description>&lt;P&gt;Thank you for the information.&lt;/P&gt;&lt;P&gt;My version is R81.20 Take 99.&lt;/P&gt;&lt;P&gt;So even if HTTPS inspection has not been configured, the default option "Revoked server certificate" is performed, so it drop the communication.&lt;/P&gt;&lt;P&gt;Checking log, it shows only Detect and this let me think that the behaviour is not to block it, but just to inform, but I'm wrong.&lt;/P&gt;&lt;P&gt;If I'm going to disable this option, I understand it is global for all sites, I was hoping there was a way to create an exception.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Aug 2025 14:56:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256150#M125</guid>
      <dc:creator>Ilovecheckpoint</dc:creator>
      <dc:date>2025-08-28T14:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256160#M126</link>
      <description>&lt;P&gt;Perhaps I was mistaken that this setting is used for Verified SNI.&lt;BR /&gt;It definitely is for HTTPS Inspection, and yes this is a global setting.&lt;BR /&gt;No action is required here, but that explains the error.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Aug 2025 19:32:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256160#M126</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-28T19:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256227#M127</link>
      <description>&lt;P&gt;I would definitely see if you can install R81.20 with recommended jumbo hotfix 105 and see if that fixes the issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 19:27:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256227#M127</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-29T19:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256228#M128</link>
      <description>&lt;P&gt;Try to make bypass rule above the current https inspection rule. Instead of url use the ip of the relevant website.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 19:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256228#M128</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-08-29T19:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256380#M129</link>
      <description>&lt;P&gt;I have noticed, for domains where I upgraded from R81.20 to R81.20, the install option is not enabled by default.&lt;/P&gt;&lt;P&gt;On domains where the firewall have been installed on R81.20, this option is enabled by default.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 11:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256380#M129</guid>
      <dc:creator>Ilovecheckpoint</dc:creator>
      <dc:date>2025-09-02T11:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: err_ssl_protocol_error on a website</title>
      <link>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256385#M130</link>
      <description>&lt;P&gt;Thats right.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 12:04:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/err-ssl-protocol-error-on-a-website/m-p/256385#M130</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-02T12:04:03Z</dc:date>
    </item>
  </channel>
</rss>

