<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS Inspection is always bypassed - &amp;quot;Inspection is not Required&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276516#M105247</link>
    <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;I’m running into an issue with HTTPS Inspection and would appreciate your insights.&lt;/P&gt;&lt;P&gt;I’ve configured HTTPS Inspection to the best of my knowledge:&lt;/P&gt;&lt;P&gt;* HTTPS Inspection is enabled on the firewall&lt;BR /&gt;* There is an outbound rule with the action set to **Inspect**&lt;BR /&gt;* The inspection certificate is properly installed on the client&lt;/P&gt;&lt;P&gt;However, inspection is never actually triggered. All traffic is consistently marked as **Bypass**, with the reason: *“Inspection is not required.”*&lt;/P&gt;&lt;P&gt;Has anyone encountered this behavior before or knows what could cause this? Are there specific conditions, rulebase settings, or blade interactions that might lead to traffic being skipped with this message?&lt;BR /&gt;&lt;BR /&gt;It's an Open server with R82 Take 91.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;BR /&gt;&lt;BR /&gt;Niko&lt;/P&gt;</description>
    <pubDate>Tue, 05 May 2026 15:36:08 GMT</pubDate>
    <dc:creator>Nikolas135096</dc:creator>
    <dc:date>2026-05-05T15:36:08Z</dc:date>
    <item>
      <title>HTTPS Inspection is always bypassed - "Inspection is not Required"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276516#M105247</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;I’m running into an issue with HTTPS Inspection and would appreciate your insights.&lt;/P&gt;&lt;P&gt;I’ve configured HTTPS Inspection to the best of my knowledge:&lt;/P&gt;&lt;P&gt;* HTTPS Inspection is enabled on the firewall&lt;BR /&gt;* There is an outbound rule with the action set to **Inspect**&lt;BR /&gt;* The inspection certificate is properly installed on the client&lt;/P&gt;&lt;P&gt;However, inspection is never actually triggered. All traffic is consistently marked as **Bypass**, with the reason: *“Inspection is not required.”*&lt;/P&gt;&lt;P&gt;Has anyone encountered this behavior before or knows what could cause this? Are there specific conditions, rulebase settings, or blade interactions that might lead to traffic being skipped with this message?&lt;BR /&gt;&lt;BR /&gt;It's an Open server with R82 Take 91.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;BR /&gt;&lt;BR /&gt;Niko&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 15:36:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276516#M105247</guid>
      <dc:creator>Nikolas135096</dc:creator>
      <dc:date>2026-05-05T15:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection is always bypassed - "Inspection is not Required"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276525#M105249</link>
      <description>&lt;P&gt;Most likely, this is going to require a TAC case.&lt;BR /&gt;I've never seen this message myself and don't see it mentioned in any TAC cases.&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 16:42:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276525#M105249</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-05-05T16:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection is always bypassed - "Inspection is not Required"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276526#M105250</link>
      <description>&lt;P&gt;Never seen it either...&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 16:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276526#M105250</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-05-05T16:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection is always bypassed - "Inspection is not Required"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276561#M105254</link>
      <description>&lt;P&gt;Thanks a lot for your fast replies. I'll open a TAC case.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2026 07:38:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276561#M105254</guid>
      <dc:creator>Nikolas135096</dc:creator>
      <dc:date>2026-05-06T07:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection is always bypassed - "Inspection is not Required"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276576#M105256</link>
      <description>&lt;P&gt;Let us know how it goes.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2026 11:33:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276576#M105256</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-05-06T11:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection is always bypassed - "Inspection is not Required"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276594#M105257</link>
      <description>&lt;P&gt;Do you have a rule which needs to see inside the traffic? For example, are you applying AV scanning?&lt;/P&gt;
&lt;P&gt;HTTPS Inspection isn't an end in itself. It's a feature to allow other inspection to work. If there's no other inspection which depends on it, maybe the firewall doesn't insert itself into the TLS negotiation because inspection is not required.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2026 14:22:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276594#M105257</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2026-05-06T14:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection is always bypassed - "Inspection is not Required"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276598#M105258</link>
      <description>&lt;P&gt;I just ran your screenshot through chatgpt and below iw aht it gave me. Not sure if you can double check these points:&lt;/P&gt;
&lt;P&gt;*****************************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="155" data-start="0"&gt;This screenshot is from a Check Point log (likely SmartLog / SmartConsole), and it’s showing how a specific connection was handled by your security policy.&lt;/P&gt;
&lt;P data-end="186" data-start="157"&gt;Here’s what each field means:&lt;/P&gt;
&lt;P data-end="212" data-start="188"&gt;&lt;STRONG data-end="212" data-start="188"&gt;Action: HTTPS Bypass&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="360" data-start="213"&gt;
&lt;LI data-end="277" data-start="213" data-section-id="1huxr67"&gt;The traffic matched a rule that &lt;STRONG data-end="276" data-start="247"&gt;bypasses HTTPS inspection&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="360" data-start="278" data-section-id="1wgdp1p"&gt;In plain terms: the firewall &lt;STRONG data-end="359" data-start="309"&gt;did NOT decrypt or inspect the SSL/TLS traffic&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="407" data-start="362"&gt;&lt;STRONG data-end="407" data-start="362"&gt;Action Reason: Inspection is not Required&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="556" data-start="408"&gt;
&lt;LI data-end="446" data-start="408" data-section-id="j7mblt"&gt;This explains &lt;EM data-end="429" data-start="424"&gt;why&lt;/EM&gt; it was bypassed.&lt;/LI&gt;
&lt;LI data-end="556" data-start="447" data-section-id="17nrylg"&gt;The policy determined that this connection is &lt;STRONG data-end="518" data-start="495"&gt;trusted or excluded&lt;/STRONG&gt;, so deep inspection wasn’t necessary.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="591" data-start="558"&gt;&lt;STRONG data-end="591" data-start="558"&gt;Policy Management: NK-CP-MGMT&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="651" data-start="592"&gt;
&lt;LI data-end="651" data-start="592" data-section-id="4b80be"&gt;This is the &lt;STRONG data-end="627" data-start="606"&gt;management server&lt;/STRONG&gt; that pushed the policy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="687" data-start="653"&gt;&lt;STRONG data-end="687" data-start="653"&gt;Policy Name: IDAwarenessPolicy&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="828" data-start="688"&gt;
&lt;LI data-end="762" data-start="688" data-section-id="1tmtk84"&gt;The connection matched a rule inside your &lt;STRONG data-end="761" data-start="732"&gt;Identity Awareness policy&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="828" data-start="763" data-section-id="1ga9g83"&gt;Likely tied to user/group-based rules rather than just IP/port.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="866" data-start="830"&gt;&lt;STRONG data-end="866" data-start="830"&gt;Policy Date: Yesterday, 16:51:30&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="945" data-start="867"&gt;
&lt;LI data-end="945" data-start="867" data-section-id="1pokg5s"&gt;Timestamp of when the policy currently installed on the gateway was applied.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="950" data-start="947" /&gt;
&lt;H3 data-end="979" data-start="952" data-section-id="18mtqz5"&gt;What this means overall&lt;/H3&gt;
&lt;P data-end="1024" data-start="980"&gt;Traffic matched a rule that explicitly says:&lt;/P&gt;
&lt;BLOCKQUOTE data-end="1072" data-start="1025"&gt;
&lt;P data-end="1072" data-start="1027"&gt;“Allow HTTPS traffic without SSL inspection.”&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P data-end="1100" data-start="1074"&gt;This is commonly done for:&lt;/P&gt;
&lt;UL data-end="1247" data-start="1101"&gt;
&lt;LI data-end="1145" data-start="1101" data-section-id="nrew9t"&gt;Trusted domains (banking, Microsoft, etc.)&lt;/LI&gt;
&lt;LI data-end="1173" data-start="1146" data-section-id="7wyl36"&gt;Privacy-sensitive traffic&lt;/LI&gt;
&lt;LI data-end="1220" data-start="1174" data-section-id="hyus19"&gt;Applications that break under SSL inspection&lt;/LI&gt;
&lt;LI data-end="1247" data-start="1221" data-section-id="itb3bl"&gt;Performance optimization&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="1252" data-start="1249" /&gt;
&lt;H3 data-end="1274" data-start="1254" data-section-id="1dz3o8e"&gt;Why this matters&lt;/H3&gt;
&lt;P data-end="1299" data-start="1275"&gt;Because it was bypassed:&lt;/P&gt;
&lt;UL data-end="1449" data-start="1300"&gt;
&lt;LI data-end="1330" data-start="1300" data-section-id="fanz43"&gt;No SSL decryption happened&lt;/LI&gt;
&lt;LI data-end="1389" data-start="1331" data-section-id="uf9uk0"&gt;No deep threat inspection inside the encrypted payload&lt;/LI&gt;
&lt;LI data-end="1449" data-start="1390" data-section-id="ohro9p"&gt;Only basic inspection (IP, port, SNI, etc.) was applied&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="1454" data-start="1451" /&gt;
&lt;H3 data-end="1485" data-start="1456" data-section-id="ogk6n0"&gt;If you’re troubleshooting&lt;/H3&gt;
&lt;P data-end="1505" data-start="1486"&gt;This log tells you:&lt;/P&gt;
&lt;UL data-end="1653" data-start="1506"&gt;
&lt;LI data-end="1576" data-start="1506" data-section-id="1dmq14q"&gt;If you expected HTTPS inspection → &lt;STRONG data-end="1576" data-start="1543"&gt;your rulebase is bypassing it&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="1653" data-start="1577" data-section-id="1bvk5ea"&gt;If something is being missed (e.g., malware detection) → this could be why&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 06 May 2026 14:44:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276598#M105258</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-05-06T14:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection is always bypassed - "Inspection is not Required"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276701#M105288</link>
      <description>&lt;P&gt;You're absolutely right. As soon as I enabled Threat Prevention, the traffic was inspected. Thank you very much!&lt;/P&gt;&lt;P&gt;Interestingly, even the support team hadn't seen that message before.&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 11:31:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-is-always-bypassed-quot-Inspection-is-not/m-p/276701#M105288</guid>
      <dc:creator>Nikolas135096</dc:creator>
      <dc:date>2026-05-08T11:31:08Z</dc:date>
    </item>
  </channel>
</rss>

