<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS inspection and Netflix in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6075#M100747</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I understand. But without inspection, Netflix will pass through without any enforcement, correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Sep 2017 22:20:32 GMT</pubDate>
    <dc:creator>Josh_Wilson</dc:creator>
    <dc:date>2017-09-08T22:20:32Z</dc:date>
    <item>
      <title>HTTPS inspection and Netflix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6071#M100743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am having difficulty preventing/blocking access to Netflix services. It appears that the HTTPS inspection blade does not try to or cannot properly inspect the HTTPS traffic to &lt;A href="https://www.netflix.com"&gt;https://www.netflix.com&lt;/A&gt;&amp;nbsp;and I am looking for some insight on how to resolve this or if it is possible.&lt;/P&gt;&lt;P&gt;I did come across this article explaining how Netflix has advanced their efforts in deploying TLS and suggests something proprietary has been done. Could this be related?&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://arstechnica.com/information-technology/2015/04/it-wasnt-easy-but-netflix-will-soon-use-https-to-secure-video-streams/" title="https://arstechnica.com/information-technology/2015/04/it-wasnt-easy-but-netflix-will-soon-use-https-to-secure-video-streams/"&gt;It wasn’t easy, but Netflix will soon use HTTPS to secure video streams | Ars Technica&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else already struggled with this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 13:17:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6071#M100743</guid>
      <dc:creator>Josh_Wilson</dc:creator>
      <dc:date>2017-09-08T13:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection and Netflix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6072#M100744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk114419"&gt;sk114419&lt;/A&gt; describes what to do.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create network objects to represent ranges or &lt;A href="https://ipinfo.io/AS2906"&gt;networks on IP addresses used by "Netflix" clients&lt;/A&gt;.&lt;/LI&gt;&lt;LI&gt;Configure the above network objects in the HTTPS Inspection Bypass rule.&lt;/LI&gt;&lt;LI&gt;Install the policy.&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 19:53:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6072#M100744</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2017-09-08T19:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection and Netflix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6073#M100745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I appreciate the response but wouldn't that SK&amp;nbsp;provide an alternative method to bypassing HTTPS inspection? I actually want to be able to inspect the traffic properly so that I can accurately "block" access using the application layer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 20:08:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6073#M100745</guid>
      <dc:creator>Josh_Wilson</dc:creator>
      <dc:date>2017-09-08T20:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection and Netflix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6074#M100746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If Netflix uses Certificate Pinning in it's HTTPS Implementation, you cannot do HTTPS Inspection on that traffic without breaking Netflix.&lt;/P&gt;&lt;P&gt;In which case, the only solution is to disable inspection for those destination IPs listed in the link &lt;A href="https://community.checkpoint.com/migrated-users/41735"&gt;https://community.checkpoint.com/people/dantr917b8439-9d5c-34f0-b86a-f0e1b0a14cbd&lt;/A&gt; provided.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 21:26:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6074#M100746</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-08T21:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection and Netflix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6075#M100747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I understand. But without inspection, Netflix will pass through without any enforcement, correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 22:20:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6075#M100747</guid>
      <dc:creator>Josh_Wilson</dc:creator>
      <dc:date>2017-09-08T22:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection and Netflix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6076#M100748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will still have enforcement as it should be possible to tell it's Netflix traffic without doing HTTPS Inspection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 22:33:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6076#M100748</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-08T22:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection and Netflix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6077#M100749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I just found a fix for this one, you need to install the Symantec intermediate cert in to the HTTPS Inspection Trust CAs area. Once I did that, I stopped getting rejected for Netflix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is Netflix getting rejected:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="netflix rejected" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61047_netflix-rejected.jpg" style="width: 620px; height: 443px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even though I told it to allow untrusted certificates in the HTTPS Validation configurations:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="https validation" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61048_netflix-validation.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I looked through the certificate chain for &lt;A href="https://www.netflix.com"&gt;https://www.netflix.com&lt;/A&gt;&amp;nbsp;and there was this Intermediate cert in there:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="netflix certificate chain" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61049_netflix-certs.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I went to Symantec and found that certificate (&lt;A class="link-titled" href="https://knowledge.symantec.com/support/ssl-certificates-support/index?page=content&amp;amp;actp=crosslink&amp;amp;id=info2045" title="https://knowledge.symantec.com/support/ssl-certificates-support/index?page=content&amp;amp;actp=crosslink&amp;amp;id=info2045"&gt;Symantec SSL Certificates Support&lt;/A&gt;&amp;nbsp;) and installed it as a Trusted CA in HTTPS Inspection:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="netflix symantec cert installed" class="image-4 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61050_netflix-installed.jpg" style="width: 620px; height: 27px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once I did that, I was no longer getting rejected and this should also allow proper enforcement of Netflix as well. On a block rule I was also able to get the UserCheck page to appear, so HTTPS inspection is working properly now.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="netflix usercheck" class="image-5 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61051_netflix-usercheck.JPG" style="width: 620px; height: 363px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2017 18:01:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6077#M100749</guid>
      <dc:creator>Eric_Oakeson</dc:creator>
      <dc:date>2017-11-22T18:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection and Netflix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6078#M100750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great tip, thanks for sharing this with the community.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2017 18:05:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6078#M100750</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-22T18:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection and Netflix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6079#M100751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update from further testing, this works on Windows, Mac, and Android devices. Still seeing issues with Apple iOS devices as they use a different URL (ios.nccp.netflix.com) which seems to have cert issues of its own, so still be aware of that one. I haven't been able to get that working yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2017 00:31:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-and-Netflix/m-p/6079#M100751</guid>
      <dc:creator>Eric_Oakeson</dc:creator>
      <dc:date>2017-11-29T00:31:15Z</dc:date>
    </item>
  </channel>
</rss>

