<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS Inspection Bypass GooglePlay in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66891#M12278</link>
    <description>&lt;P&gt;We have scanguns that are having trouble getting to the GooglePlay store. It appears based on errors that GooglePlay does not use the Android Certificate store to use our https inspection certificate.&lt;/P&gt;&lt;P&gt;I have opened up the clients to bypass the following URL's but am still having issues:&lt;/P&gt;&lt;P&gt;*.google.com&lt;/P&gt;&lt;P&gt;google.com&lt;/P&gt;&lt;P&gt;*.googleapis.com&lt;/P&gt;&lt;P&gt;googleapis.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't see other google entries in the inspection and according to the logs the clients are getting bypassed, but it hasn't been until I bypass all https inspection for the specific client that it is fully able to connect to the GooglePlay store, register, and download files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Nov 2019 16:51:54 GMT</pubDate>
    <dc:creator>Wyatt_Felger</dc:creator>
    <dc:date>2019-11-08T16:51:54Z</dc:date>
    <item>
      <title>HTTPS Inspection Bypass GooglePlay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66891#M12278</link>
      <description>&lt;P&gt;We have scanguns that are having trouble getting to the GooglePlay store. It appears based on errors that GooglePlay does not use the Android Certificate store to use our https inspection certificate.&lt;/P&gt;&lt;P&gt;I have opened up the clients to bypass the following URL's but am still having issues:&lt;/P&gt;&lt;P&gt;*.google.com&lt;/P&gt;&lt;P&gt;google.com&lt;/P&gt;&lt;P&gt;*.googleapis.com&lt;/P&gt;&lt;P&gt;googleapis.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't see other google entries in the inspection and according to the logs the clients are getting bypassed, but it hasn't been until I bypass all https inspection for the specific client that it is fully able to connect to the GooglePlay store, register, and download files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2019 16:51:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66891#M12278</guid>
      <dc:creator>Wyatt_Felger</dc:creator>
      <dc:date>2019-11-08T16:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass GooglePlay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66899#M12279</link>
      <description>What version of code?&lt;BR /&gt;If you’re not in R80.30 or R80.20 JHF 117+, I strongly encourage upgrading.&lt;BR /&gt;The added support for SNI should help with this.</description>
      <pubDate>Fri, 08 Nov 2019 17:24:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66899#M12279</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-08T17:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass GooglePlay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66901#M12280</link>
      <description>&lt;P&gt;R77.30&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":zipper_mouth_face:"&gt;🤐&lt;/span&gt; - We are working to move to R80, but not there yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2019 17:37:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66901#M12280</guid>
      <dc:creator>Wyatt_Felger</dc:creator>
      <dc:date>2019-11-08T17:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass GooglePlay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66958#M12281</link>
      <description>You should check the non-Google HTTPS entries as they may provide a clue at other things you may need to set bypass rules for.</description>
      <pubDate>Sat, 09 Nov 2019 10:44:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66958#M12281</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-09T10:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass GooglePlay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66965#M12282</link>
      <description>&lt;P&gt;Most google apps have SSL Pinning. In other words they will not work if a non google certificate is presented. The following solution applies to R77.30 and R80.10. R80.20 an .30 have new SSL inspection engines and don't use these flags anymore.&lt;/P&gt;&lt;P&gt;When you perform SSL Inspection, even if you set it to bypass the engine stills checks the Client Hello of the SSL Handshake, this is enough to break some applications.&lt;/P&gt;&lt;P&gt;Together with your exceptions I suggest you to set up Enhaced SSL Bypass (Probe bypass detailed on &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104717#Improvements%20in%20HTTPS%20Inspection%20Bypass%20mechanism" target="_self"&gt;sk104717&lt;/A&gt;&amp;nbsp;) default is off and you can set it on the fly:&lt;/P&gt;&lt;P&gt;on: fw ctl set int enhanced_ssl_inspection 1&lt;BR /&gt;off: fw ctl set int enhanced_ssl_inspection 0&lt;/P&gt;&lt;P&gt;For more information reffer to the provided SK, keep in mind that you may have some compatibility issues with sites using SNI.&lt;/P&gt;&lt;P&gt;If you still have issues I would suggest you to not inspect at all the mobile devices LAN. Don't use a bypass action, just be sure to not include the prefix on your SSL Policy.&lt;/P&gt;&lt;P&gt;You can find more information in my other post about SSL Inspection:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Outbound-SSL-Inspection-A-war-story/m-p/58647" target="_self"&gt;https://community.checkpoint.com/t5/General-Topics/Outbound-SSL-Inspection-A-war-story/m-p/58647&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let us know how it goes&amp;nbsp;&lt;/P&gt;&lt;P&gt;___&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2019 12:24:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-GooglePlay/m-p/66965#M12282</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-11-09T12:24:25Z</dc:date>
    </item>
  </channel>
</rss>

