<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection for Proxy environment in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63971#M12311</link>
    <description>&lt;P&gt;Thank you !&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2019 14:47:19 GMT</pubDate>
    <dc:creator>kulwinder_barhe</dc:creator>
    <dc:date>2019-09-30T14:47:19Z</dc:date>
    <item>
      <title>HTTPS Inspection for Proxy environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63862#M12306</link>
      <description>&lt;P&gt;What are the minimum hardware requirements and support for HTTPS Inspection. I have a client with 2200 hardware and 77.20 firmware. Any specific Pros and Cons I need to know as my client is having 2 web servers in proxy environment and lot of issues when we are enabling this feature. Do I need to upgrade firmware ?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 18:02:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63862#M12306</guid>
      <dc:creator>kulwinder_barhe</dc:creator>
      <dc:date>2019-09-27T18:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Proxy environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63877#M12307</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Both your appliance and OS version are quite old:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The 2200 appliance has support until 2022 but the hardware is probably outdated for today requirements. If you are going to keep using this I strongly advise to add more RAM to it if possible.&lt;/LI&gt;&lt;LI&gt;R77.20 is totally outdated, it doesn't have support since August 2017. Supported versions are R80.10, R80.20 and R80.30. All three of them have MANY improvements to SSL Inspection. If it's a stand alone deployment then you will not be able to upgrade to these versions.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Another point to check if how many blades do you have enabled and throughput. Last but not last if you have the management server inside your 2200 (Stand alone deployment) I hardly doubt that you have resources to enable SSL Inspection.&lt;/P&gt;&lt;P&gt;You can refer to my post which has some tips in how to implement SSL Inspection:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Outbound-SSL-Inspection-A-war-story/m-p/58647" target="_self"&gt;Outbound SSL Inspection: A war story&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To summarize:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Check current CPU and memory utilization with SmartView Monitor, output from top and free -m. If CPU is average %45 or you have spikes and/or you are swapping memory then it's a bad idea.&lt;/LI&gt;&lt;LI&gt;Check active blades and current throughput and compare it with the 2200 datasheet&lt;/LI&gt;&lt;LI&gt;Use R80.XX - You cannot do this if you have the management on the same appliance.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Hope it helps&lt;/P&gt;</description>
      <pubDate>Sat, 28 Sep 2019 06:22:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63877#M12307</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-09-28T06:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Proxy environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63890#M12308</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23497"&gt;@kulwinder_barhe&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My previous post with a lot of more detail was tagged as spam, until it is recovered here is my advise:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HTTPS Inspection is really resource intensive.&lt;/LI&gt;&lt;LI&gt;Appliance 2200 is old, you will probably need to add more RAM for SSL Inspection (Check with free -m / top / Smartview Monitor).&lt;/LI&gt;&lt;LI&gt;R77.20 is out of support since 2017, you will need R80.10 / R80.20 / R80.30.&lt;/LI&gt;&lt;LI&gt;R80.XX comes with tons of improvements for SSL Inspection.&lt;/LI&gt;&lt;LI&gt;If you have a stand alone deployment (Management + GW in the same box) then you cannot upgrade to R80.XX. You will need to separate them (Distributed deployment)&lt;/LI&gt;&lt;LI&gt;Reffer to my post&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Outbound-SSL-Inspection-A-war-story/m-p/58647" target="_self"&gt;Outbound SSL Inspection: A war story&lt;/A&gt;&amp;nbsp;for advises on deploying HTTPS Inspection.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope it helps&lt;/P&gt;&lt;P&gt;___&lt;/P&gt;</description>
      <pubDate>Sat, 28 Sep 2019 15:54:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63890#M12308</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-09-28T15:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Proxy environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63893#M12309</link>
      <description>Not sure why this was flagged as spam, but is not now.</description>
      <pubDate>Sat, 28 Sep 2019 20:55:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63893#M12309</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-28T20:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Proxy environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63894#M12310</link>
      <description>If you want to run HTTPS Inspection, you really need to be running on the latest release (R80.30).&lt;BR /&gt;If your 2200 has 4GB, you can do that, assuming Security Management is on a different appliance.&lt;BR /&gt;Even so, the 2200 has fairly limited CPU and HTTPS Inspection makes extensive use of it.&lt;BR /&gt;I would strongly consider replacing the 2200 with a newer, stronger appliance.</description>
      <pubDate>Sat, 28 Sep 2019 21:04:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63894#M12310</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-28T21:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Proxy environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63971#M12311</link>
      <description>&lt;P&gt;Thank you !&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2019 14:47:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Proxy-environment/m-p/63971#M12311</guid>
      <dc:creator>kulwinder_barhe</dc:creator>
      <dc:date>2019-09-30T14:47:19Z</dc:date>
    </item>
  </channel>
</rss>

