<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5129#M101214</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rule 2 uses the topology table to ensure that if you have multiple interfaces connected to internal networks, the traffic flow for internal traffic is afforded free movement between those interfaces across the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rule 4 will deny internet access to known applications. It’s the standard clean-up rule for the application blade.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Feb 2018 18:41:11 GMT</pubDate>
    <dc:creator>Stuart_Green</dc:creator>
    <dc:date>2018-02-06T18:41:11Z</dc:date>
    <item>
      <title>HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5114#M101199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Until recently we'd had an application-based rule which covered HTTPS inspection for Office 365 nicely but in the past month or so, something has changed at the Office 365 end which means that they don't play nicely any more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To that end, I've visited Microsoft's Office 365 IP address and URL pages to get all of the IP addresses and URLs to craft destination-based rules for HTTPS Inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it seems that Microsoft aren't entirely truthful when it comes to giving out their IP addresses as it seems that some traffic is still inspected and a basic install of Office 2016 can't complete as the streaming side of things doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turn HTTPS inspection off and it'll stream nicely and do everything it should do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone had any success in getting this working with HTTPS Inspection on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 16:27:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5114#M101199</guid>
      <dc:creator>Stuart_Green</dc:creator>
      <dc:date>2017-08-10T16:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5115#M101200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The main issue is, as you noted, excluding all the various IP addresses, which change from time to time.&lt;/P&gt;&lt;P&gt;We are working to address this limitation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 19:40:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5115#M101200</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-10T19:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5116#M101201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dameon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a workaround? &amp;nbsp;It isn't just a problem with Office 365 but is also starting to creep in to Adobe Creative Cloud and various parts of that are randomly stopping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Creating the hosts in SmartConsole is fine but as IP addresses of FQDNs change, the host needs to change too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I understand it, using the Application-based approach isn't foolproof as the application needs to be detected first so what can be done in the interim?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 21:42:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5116#M101201</guid>
      <dc:creator>Stuart_Green</dc:creator>
      <dc:date>2017-08-10T21:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5117#M101202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not aware of a clever workaround here.&lt;/P&gt;&lt;P&gt;It's something I know we are working to address, but I don't believe there is a finalized&amp;nbsp;timeline.&lt;/P&gt;&lt;P&gt;I've asked R&amp;amp;D to comment on this thread who can hopefully provide a little more color to the situation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 22:38:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5117#M101202</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-10T22:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5118#M101203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what i know there is an sk that says exactly how to configure office365. This application should automaticly update and that is they way to configure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem with office365 and https inspection that i have noticed were only with skype applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working in a project that will automaticly update an dynamic object woth data from microsoft api&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 06:17:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5118#M101203</guid>
      <dc:creator>Dor_Marcovitch</dc:creator>
      <dc:date>2017-08-11T06:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5119#M101204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My guess is the SK you're talking about is:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112354" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112354"&gt;How to allow Office 365 services in Application Control R77.30 and above&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This does require HTTPS Inspection to be configured.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 06:29:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5119#M101204</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-11T06:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5120#M101205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep, so that sk is fine BUT the most it mentions about HTTPS Inspection is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;"&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Of course, HTTPS Inspection is mandatory for the proper usage of the Office 365 services"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;and HTTPS Inspection still inspects some of the packets which kills the streaming installation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Even in sk110679 which sk112354 refers to, the most that is mentioned is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;HTTPS Inspection&lt;/STRONG&gt;&lt;/EM&gt; is mandatory on Security Gateway to achieve proper detection."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So both SKs in this instance aren't that clear as to what needs to be done within HTTPS Inspection to allow the streaming install to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Disable HTTPS Inspection and the streaming install works. &amp;nbsp;Switch HTTPS Inspection back on and the install fails. &amp;nbsp;That even rules out Geo Protection and IPS meddling...!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 08:26:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5120#M101205</guid>
      <dc:creator>Stuart_Green</dc:creator>
      <dc:date>2017-08-11T08:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5121#M101206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have probe bypass enabled? I had issues with most microsoft services when probe bypass was enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw ctl get int enhanced_ssl_inspection&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 12:17:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5121#M101206</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2017-08-11T12:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5122#M101207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;enhanced_ssl_inspection = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No dice there, then...!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 12:49:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5122#M101207</guid>
      <dc:creator>Stuart_Green</dc:creator>
      <dc:date>2017-08-11T12:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5123#M101208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;We plan to introduce the support for dynamically updated office-365 objects. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;These objects will be supported in both Access Policy and in HTTPS Inspection policy for both source and destination columns.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Plan is to release a special HF on top of R80.10 with this capability in Q4 2017, and to support this capability in R80.20.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Could you share some more info regrading what IPs are not included in Microsoft feed as you tested it?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Aug 2017 05:16:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5123#M101208</guid>
      <dc:creator>Limor_Ganon</dc:creator>
      <dc:date>2017-08-13T05:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5124#M101209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Was this released for R80.X? Is this Management, Gateway or Both hot-fix?&lt;/P&gt;&lt;P&gt;Any plans to introduce HF for pre-R80 platforms? We are running MDS and has no ability to upgrade to R80 due to multiple reasons.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jan 2018 13:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5124#M101209</guid>
      <dc:creator>Sergej_Gurenko</dc:creator>
      <dc:date>2018-01-09T13:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5125#M101210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both&amp;nbsp;gateway and management fixes will be required.&lt;/P&gt;&lt;P&gt;As far as I know there are no plans to provide this hotfix on R77.30.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jan 2018 14:34:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5125#M101210</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-09T14:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5126#M101211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guys - I wish to use application control to permit O365 destined traffic as described in sk112354.&lt;/P&gt;&lt;P&gt;Could someone please explain the suggested rules below as per sk112354: -&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62863_pastedImage_1.png" style="width: 620px; height: 188px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rule 2 has source and destination as 'internal networks'?&lt;/P&gt;&lt;P&gt;rule 4 - will this deny all other internet bound traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Feb 2018 09:53:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5126#M101211</guid>
      <dc:creator>heavysoul</dc:creator>
      <dc:date>2018-02-05T09:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5127#M101212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any ETA for this feature?&lt;/P&gt;&lt;P&gt;Furthermore, is this also applicable for Skype for Business Online?&lt;/P&gt;&lt;P&gt;I have the challenge to enable Skype for Business Online, but would like the best possible security there.&lt;/P&gt;&lt;P&gt;Dynamic objects would help here, as I can define the exact rules for S4B.&lt;/P&gt;&lt;P&gt;The plan would be, to allow only connections to Skype with the ports for a defined user group, every other traffic from these clients will still need to pass my proxy etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Georg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2018 09:44:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5127#M101212</guid>
      <dc:creator>Georg_Reichau</dc:creator>
      <dc:date>2018-02-06T09:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5128#M101213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Georg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparently this feature is coming in R80.20 which is in EA at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Skype, if you have Identity Awareness running hooked in to AD/LDAP/Internal DB, you can create an Access Role and then define an application policy for the Skype application that uses the access role as the source.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you’re using HTTPS Inspection you’ll need to add the IP Address group as the destination for the bypass rule so that the first packet doesn’t get inspected.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2018 18:33:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5128#M101213</guid>
      <dc:creator>Stuart_Green</dc:creator>
      <dc:date>2018-02-06T18:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5129#M101214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rule 2 uses the topology table to ensure that if you have multiple interfaces connected to internal networks, the traffic flow for internal traffic is afforded free movement between those interfaces across the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rule 4 will deny internet access to known applications. It’s the standard clean-up rule for the application blade.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2018 18:41:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5129#M101214</guid>
      <dc:creator>Stuart_Green</dc:creator>
      <dc:date>2018-02-06T18:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5130#M101215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; background-color: #ffffff;"&gt;dynamically updated office-365 objects in the access rule means you will update the o365 ip addresses so that we don't have to use HTTPS Inspection to detect the applications?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2018 09:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5130#M101215</guid>
      <dc:creator>Kevin_Petermann</dc:creator>
      <dc:date>2018-02-19T09:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5131#M101216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;many thanks Stuart&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2018 16:55:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5131#M101216</guid>
      <dc:creator>heavysoul</dc:creator>
      <dc:date>2018-02-19T16:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5132#M101217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i really enjoy this statesments "&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;It’s the standard clean-up rule for the application blade"... when when it will be changed R80.10 do little work about this cleanup rule to be really cleanup rule?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;by the way if those rule does not work contact checkpoin TAC they say this configuration should work...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2018 19:57:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5132#M101217</guid>
      <dc:creator>Dor_Marcovitch</dc:creator>
      <dc:date>2018-02-19T19:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and Office 365 - Anyone got it playing nicely?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5133#M101218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean the default cleanup rule in App Control being "drop" instead of "accept"?&lt;/P&gt;&lt;P&gt;The reason the default is what it is is because in R77.30 and earlier, the cleanup rule for the App Control rulebase was Accept.&lt;/P&gt;&lt;P&gt;This is because App Control was designed to work more like a blacklist, not like a whitelist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For R80.10 gateways where a unified policy can be deployed, you can&amp;nbsp;deploy a "whitelist" or a "blacklist" policy.&lt;/P&gt;&lt;P&gt;Further, you can set the default cleanup rule for the specific layer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63211_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2018 20:10:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-Office-365-Anyone-got-it-playing-nicely/m-p/5133#M101218</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-19T20:10:25Z</dc:date>
    </item>
  </channel>
</rss>

