<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection and P-521 certificate in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/72989#M11755</link>
    <description>&lt;P&gt;Thank you for your post, sorry if I didn't ask the question well.&lt;/P&gt;&lt;P&gt;I understood it well RSA 2048 certificate and P-521 ECC certificate they are not compatible ?&lt;/P&gt;&lt;P&gt;HTTPS Inspection using for inspection website only RSA 2048 certificate or RSA 4096 certificate ?&lt;/P&gt;&lt;P&gt;My question is regarding HTTPS Inspection site-to-site VPN with preshared key and with P-521 ECC as encryption ?&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jan 2020 12:11:48 GMT</pubDate>
    <dc:creator>RoD</dc:creator>
    <dc:date>2020-01-22T12:11:48Z</dc:date>
    <item>
      <title>HTTPS Inspection and P-521 certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/72969#M11753</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have question about site-to-site VPN with P-521 ECC encryption and HTTPS Inspection.&lt;/P&gt;&lt;P&gt;It it possible to have two certificate for HTTPS Inspection,&lt;/P&gt;&lt;P&gt;one RSA 2048 certificate for website and second P-521 ECC certificate for&amp;nbsp;site-to-site VPN ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 10:43:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/72969#M11753</guid>
      <dc:creator>RoD</dc:creator>
      <dc:date>2020-01-22T10:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and P-521 certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/72986#M11754</link>
      <description>&lt;P&gt;For HTTPS inspection you need a SUB-CA installed on your gateway not only a certificate.&lt;/P&gt;
&lt;P&gt;These SUB-CA and the certificate for Site2Site VPN is configured and stored at different places. Following this you don't need to have one for both feature.&lt;/P&gt;
&lt;P&gt;certificate for VPN:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN_cert.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4087iEA7A6B110730A0EE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN_cert.png" alt="VPN_cert.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;SUB-CA for HTTPS-inspection:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HTTPS_inspection.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4088i0D63B3E1B7759238/image-size/medium?v=v2&amp;amp;px=400" role="button" title="HTTPS_inspection.png" alt="HTTPS_inspection.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 11:52:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/72986#M11754</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-01-22T11:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and P-521 certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/72989#M11755</link>
      <description>&lt;P&gt;Thank you for your post, sorry if I didn't ask the question well.&lt;/P&gt;&lt;P&gt;I understood it well RSA 2048 certificate and P-521 ECC certificate they are not compatible ?&lt;/P&gt;&lt;P&gt;HTTPS Inspection using for inspection website only RSA 2048 certificate or RSA 4096 certificate ?&lt;/P&gt;&lt;P&gt;My question is regarding HTTPS Inspection site-to-site VPN with preshared key and with P-521 ECC as encryption ?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 12:11:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/72989#M11755</guid>
      <dc:creator>RoD</dc:creator>
      <dc:date>2020-01-22T12:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and P-521 certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/73049#M11756</link>
      <description>The certificates used for Site-to-Site VPN and HTTPS Inspection have absolutely nothing to do with each other.&lt;BR /&gt;They are completely independent of each other and configured in different places in the UI.&lt;BR /&gt;&lt;BR /&gt;P-521 support is in R80.30.&lt;BR /&gt;Believe it is also in R80.20 with a recent Jumbo Hotfix.&lt;BR /&gt;If you are on an earlier release, you will need to upgrade.</description>
      <pubDate>Wed, 22 Jan 2020 19:53:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/73049#M11756</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-01-22T19:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and P-521 certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/73050#M11757</link>
      <description>&lt;P&gt;I believe you should explain more detailed what do you want to do.&lt;/P&gt;
&lt;P&gt;As I wrote and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned, HTTPS inspection and site2site VPN are different things and both are using different certificates.&lt;/P&gt;
&lt;P&gt;RoD, more information about your need would be very helpful to give you the right answers.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 20:09:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/73050#M11757</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-01-22T20:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and P-521 certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/73056#M11758</link>
      <description>&lt;P&gt;Thank you Wolfgang and PhoneBoy for yours help.&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have one laptops that have Site-to-Site VPN to one data center in Germany,&lt;BR /&gt;and this connection will go through 3100 or 3600 firewall.&lt;/P&gt;&lt;P&gt;My original plan was that 3100 firewall inspect this Site-to-Site VPN with HTTPS Inspection.&lt;/P&gt;&lt;P&gt;I think that is better that 3100 firewall create Site-to-Site VPN to this data center in Germany,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 20:45:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/73056#M11758</guid>
      <dc:creator>RoD</dc:creator>
      <dc:date>2020-01-22T20:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and P-521 certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/73060#M11759</link>
      <description>&lt;P&gt;RoD,&lt;/P&gt;
&lt;P&gt;I think you are mixing some of the technologies.&lt;/P&gt;
&lt;P&gt;laptop with site2site VPN ? sounds like more then a remote access VPN.&lt;/P&gt;
&lt;P&gt;You can‘t inspect an IPSEC-Tunnel with HTTPS inspection. &amp;nbsp;But you can inspect the traffic coming through the tunnel on one of the endpoints of the tunnel. If these traffic will be HTTPS you can inspect with HTTPS inspection.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 20:57:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/73060#M11759</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-01-22T20:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection and P-521 certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/73068#M11760</link>
      <description>&lt;P&gt;I forgot to add my laptop with my old hardware firewall,&lt;/P&gt;&lt;P&gt;I decided that all my site-to-site VPN go from new Check Point firewall&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 21:19:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-and-P-521-certificate/m-p/73068#M11760</guid>
      <dc:creator>RoD</dc:creator>
      <dc:date>2020-01-22T21:19:48Z</dc:date>
    </item>
  </channel>
</rss>

