<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with HTTPS Inspection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-HTTPS-Inspection/m-p/80816#M11471</link>
    <description>&lt;P&gt;Are you using the same certificate for both inbound and outbound? The issue you are having, which direction it happens with?&lt;/P&gt;</description>
    <pubDate>Sat, 04 Apr 2020 09:38:52 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2020-04-04T09:38:52Z</dc:date>
    <item>
      <title>Problem with HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-HTTPS-Inspection/m-p/80759#M11470</link>
      <description>&lt;DIV class="lia-quilt-row lia-quilt-row-message-subject"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-subject-content"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;&lt;DIV class="topic-subject-wrapper"&gt;&lt;DIV class="lia-message-subject lia-component-message-view-widget-subject"&gt;&lt;DIV class="MessageSubject"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-quilt-row lia-quilt-row-message-body"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-body-content"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;I am having an issue with HTTPS inspection and the user check page.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have set up inbound/outbound in our DR envrionent successfully, I am now working on our production environment, however I am running into the following error.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;when I go to any https site the inspection works correctly I get our ca issuing the cert more or less as the man in the middle and the site opens with no errors, when I go to any site which is subject to URLF or APC I get the following error,&lt;/P&gt;&lt;P&gt;SAN cert is in place, this error is on all browsers&lt;BR /&gt;Your connection is not private&lt;BR /&gt;Attackers might be trying to steal your information from dcfw-private.xxxx.net (for example, passwords, messages, or credit cards). Learn more&lt;BR /&gt;NET::ERR_CERT_COMMON_NAME_INVALID&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;when I click on the Advanced the following error&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This server could not prove that it is dcfw-private.xxxx.net; its security certificate is from dcfw.xxxx.net. This may be caused by a misconfiguration or an attacker intercepting your connection.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Keeping in mind, I configured everything the same including the SAN cert except for the names and IP's. All certs look the same with SAN, CN, Subject they have the same path with all the same Certs inline&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 03 Apr 2020 15:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-HTTPS-Inspection/m-p/80759#M11470</guid>
      <dc:creator>Ricardo_Galvan</dc:creator>
      <dc:date>2020-04-03T15:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-HTTPS-Inspection/m-p/80816#M11471</link>
      <description>&lt;P&gt;Are you using the same certificate for both inbound and outbound? The issue you are having, which direction it happens with?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2020 09:38:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-HTTPS-Inspection/m-p/80816#M11471</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-04-04T09:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-HTTPS-Inspection/m-p/80845#M11472</link>
      <description>&lt;P&gt;Because you're not getting a certificate generated by HTTPS Inspection in this case, you are getting the UserCheck certificate, which by default is a self-signed certificate.&lt;/P&gt;
&lt;P&gt;You can replace this certificate with one signed by a CA the end user browser already trusts from here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2020-04-04 at 8.29.40 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5386i2F8CADC8190BC6DC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-04-04 at 8.29.40 PM.png" alt="Screen Shot 2020-04-04 at 8.29.40 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Otherwise, you will have to configure the end user browsers to trust this self-signed certificate.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Apr 2020 03:31:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-HTTPS-Inspection/m-p/80845#M11472</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-05T03:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-HTTPS-Inspection/m-p/80961#M11473</link>
      <description>&lt;P&gt;thank you all for assistance in figuring this one out..&amp;nbsp;&lt;/P&gt;&lt;P&gt;all certificates are correct and in the correct location on the gateways and machines. this was a self inflicted wound. we have two FQDN's resloving to the same IP when only one is correct for the portal to work correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ric&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 13:08:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-HTTPS-Inspection/m-p/80961#M11473</guid>
      <dc:creator>Ricardo_Galvan</dc:creator>
      <dc:date>2020-04-06T13:08:26Z</dc:date>
    </item>
  </channel>
</rss>

