<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there SNI support for inbound HTTPS inspection in R80.20? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/65402#M12852</link>
    <description>&lt;P&gt;Better use R80.30:-)&lt;/P&gt;</description>
    <pubDate>Sun, 20 Oct 2019 19:54:29 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2019-10-20T19:54:29Z</dc:date>
    <item>
      <title>Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/53423#M12839</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;on gws R80.20 can I do HTTPS inspection on inbound connections that require SNI since on the server there are some virtual hosts with different certificates? If yes how?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 14:35:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/53423#M12839</guid>
      <dc:creator>Paolo_Francese</dc:creator>
      <dc:date>2019-05-14T14:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/53720#M12840</link>
      <description>Not sure why it is necessary to inspect the SNI since the HTTPS Inspection sees the actual URL.&lt;BR /&gt;A more relevant question might be: do we duplicate the SNI from the client as part of the connection we made to the server?&lt;BR /&gt;Not sure.</description>
      <pubDate>Fri, 17 May 2019 17:16:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/53720#M12840</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-17T17:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/53999#M12841</link>
      <description>Sorry, maybe I was not clear enough. My question is: is there SNI support in R80.20?&lt;BR /&gt;&lt;BR /&gt;What I would like to do is inspect HTTPS traffic that go toward some virtual hosts running on a server behind CP gws. Every virtual host has its own certificate.&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Tue, 21 May 2019 09:14:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/53999#M12841</guid>
      <dc:creator>Paolo_Francese</dc:creator>
      <dc:date>2019-05-21T09:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/54003#M12842</link>
      <description>&lt;P&gt;Not sure is this your expect.&lt;/P&gt;&lt;P&gt;R80.30&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;State-of-the-Art HTTPS Inspection:&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;New SSL Inspection Patent Pending Technologies. Delivering the power to inspect SSL-encrypted network traffic with secure &lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;SNI&lt;/U&gt; &lt;/EM&gt;&lt;/STRONG&gt;verification improvements.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 10:24:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/54003#M12842</guid>
      <dc:creator>Kosin_Usuwanthi</dc:creator>
      <dc:date>2019-05-21T10:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/54045#M12843</link>
      <description>Most of the requests for support for SNI are usually about Outbound Inspection.&lt;BR /&gt;More specifically, it's to see what site is really being accessed without resorting to HTTPS Inspection.&lt;BR /&gt;&lt;BR /&gt;With inbound HTTPS Inspection, the connection will terminate on the gateway.&lt;BR /&gt;This requires the private certificate of the site in question.&lt;BR /&gt;We'll be able to see the exact URL the end user specifies in this case.&lt;BR /&gt;As such, we don't need SNI.&lt;BR /&gt;&lt;BR /&gt;A network diagram would be very helpful to understand what you're trying to achieve.</description>
      <pubDate>Tue, 21 May 2019 15:29:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/54045#M12843</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-21T15:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/63850#M12844</link>
      <description>&lt;P&gt;"With inbound HTTPS Inspection, the connection will terminate on the gateway.&lt;BR /&gt;This requires the private certificate of the site in question.&lt;BR /&gt;We'll be able to see the exact URL the end user specifies in this case."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The URL is encrypted in the TLS sessions so the gateway needs to see the SNI, read what host the client needs to reach and select the right certificate to expose.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So in my opinion the SNI support it's necessary in inboud https inspection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 15:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/63850#M12844</guid>
      <dc:creator>Michele_Gullia</dc:creator>
      <dc:date>2019-09-27T15:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/63870#M12845</link>
      <description>&lt;P&gt;The URL being accessed is part of the HTTP request, which doesn't require SNI to see.&lt;BR /&gt;I've also never heard of anyone having inbound SNI issues.&lt;BR /&gt;In any case, we do SNI validation as part of R80.30.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 22:51:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/63870#M12845</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-27T22:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/63939#M12846</link>
      <description>&lt;P&gt;What I do not understand is:&lt;/P&gt;&lt;P&gt;if I've a HTTPS server with only one IP and 10 virtual hosts, this server is behind a CP firewall how can I inspect traffic?&lt;/P&gt;&lt;P&gt;I cannot use HTTPS inspection because I've 10 certificates and only one IP, writing HTTPS inspection rule require to have one IP and one certificate, or am I wrong?&lt;/P&gt;&lt;P&gt;B-)&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2019 09:12:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/63939#M12846</guid>
      <dc:creator>Paolo_Francese</dc:creator>
      <dc:date>2019-09-30T09:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/63977#M12847</link>
      <description>With 10 different certificates, it definitely would not work.&lt;BR /&gt;At a minimum, you'd have to create a new certificate that would be valid for all 10 hosts.&lt;BR /&gt;Specifically, it would have to list all 10 hosts in the Subject Alternate Name (SAN) field.&lt;BR /&gt;This will allow the remote browser to validate the certificate regardless of which of the 10 hosts you're ultimately accessing.&lt;BR /&gt;This certificate would then be used for Inbound SSL Inspection for all 10 sites.&lt;BR /&gt;Again, none of this has anything to do with SNI, which only matters when we're not terminating the TLS connection.&lt;BR /&gt;&lt;BR /&gt;What I don't know is whether or not you can leave the certificate as-is on the other hosts.&lt;BR /&gt;Assuming the Security Gateway can validate those certificates as valid, I assume it would still work.&lt;BR /&gt;</description>
      <pubDate>Mon, 30 Sep 2019 15:25:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/63977#M12847</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-30T15:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/64024#M12848</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my case I need to block external user to access some website behide the gateway.&lt;/P&gt;&lt;P&gt;I have use custom application tool (&lt;SPAN&gt;sk103051)&lt;/SPAN&gt; for custom SSL traffic with SNI. It works for blocked some website from same IP address.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 04:50:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/64024#M12848</guid>
      <dc:creator>Kosin_Usuwanthi</dc:creator>
      <dc:date>2019-10-01T04:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/64992#M12849</link>
      <description>&lt;P&gt;We have more than a hundred certificates in the same webserver (half of them are wildcards) and adding/replacing every month. To use only one certificate, even a SAN certificate, is not an option for us.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Do you know if it's there any chance to allow more than one certificate assigned to the same destination host for the https inbound analysis rules?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Regards!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 10:05:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/64992#M12849</guid>
      <dc:creator>Alejandro_Ferna</dc:creator>
      <dc:date>2019-10-15T10:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/65387#M12850</link>
      <description>This is not possible because of how TLS works, i.e. it's not a Check Point specific limitation.&lt;BR /&gt;Specifically, the server must present its server certificate before the client can communicate what host it is connecting to via SNI.&lt;BR /&gt;As such, the server certificate must be valid for all possible servers accessible from that IP address.</description>
      <pubDate>Sat, 19 Oct 2019 21:17:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/65387#M12850</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-19T21:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/65400#M12851</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/15009"&gt;@Paolo_Francese&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;R80.20 with enabled HTTPS interception:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;If the https interseption is enabled, the parameter &lt;STRONG&gt;host&lt;/STRONG&gt; &lt;STRONG&gt;from http&lt;/STRONG&gt; can be used for the url because the traffic is analyzed by active streaming. &lt;SPAN&gt;Check Point Active Streaming (CPAS) allow the changing of data, we play the role of “man in the middle”. CPAS breaks the connection into two parts using our own stack – this mean, we are responsible for all the stack work (dealing with options, retransmissions, timers etc.). An application is register to CPAS when a connection start and supply callbacks for event handler and read handler. Several protocols uses CPAS, for example: HTTPS, VoIP (SIP, Skinny/SCCP, H.323, etc.), Security Servers processes, etc.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;CPAS breaks the HTTPS connection into two parts using our own stack – this mean, we are responsible for all the stack work (dealing with options, retransmissions, timers etc.)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More read here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Security-Gateway-Architecture-Content-Inspection/td-p/41665" target="_self"&gt;R80.x Security Gateway Architecture (Content Inspection)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;R80.20 without enabled HTTPS interception:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;If the https interseption is disabled, &lt;STRONG&gt;SNI is used&lt;/STRONG&gt; to recognize the virtual URL for &lt;STRONG&gt;application control &lt;/STRONG&gt;and&lt;STRONG&gt; url filtering&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;More read here:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/general-topics/10433/1/URL%20Filtering%20using%20SNI%20for%20HTTPS%20websites.pdf" target="_self"&gt;URL Filtering using SNI for HTTPS websites.pdf&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2019 20:50:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/65400#M12851</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-10-20T20:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/65402#M12852</link>
      <description>&lt;P&gt;Better use R80.30:-)&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2019 19:54:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/65402#M12852</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-10-20T19:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/65856#M12853</link>
      <description>R80.20 with JHF 117 and above apparently has the improved SNI support.&lt;BR /&gt;If you're on an earlier JHF, we are not looking at SNI.</description>
      <pubDate>Fri, 25 Oct 2019 01:31:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/65856#M12853</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-25T01:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/66596#M12854</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When hosting different websites with different certificates (no wildcard) on the same IP address, it is not possible to configure this at the moment, so I guess this means there is no SNI support for inbound HTTPS?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 13:52:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/66596#M12854</guid>
      <dc:creator>SolidBE</dc:creator>
      <dc:date>2019-11-05T13:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/66602#M12855</link>
      <description>Again, this issue has nothing to do with (lack of) SNI support.&lt;BR /&gt;It's a function of how TLS works.&lt;BR /&gt;If a given IP serves multiple HTTPS websites, the certificate presented must be valid for all the websites.</description>
      <pubDate>Tue, 05 Nov 2019 14:37:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/66602#M12855</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-05T14:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/66604#M12856</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;It is possible to configure multiple independent certificates (different domains, so no wildcard possible) on a single IP. This only works with browsers and webservers that support SNI. But since this is currently not configurable in the HTTPS inspection I suppose this feature is not supported.&lt;/P&gt;&lt;P&gt;Or will it work if we add multiple rules with the same source IP, destination IP and port number, but different inbound certificates?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 14:53:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/66604#M12856</guid>
      <dc:creator>SolidBE</dc:creator>
      <dc:date>2019-11-05T14:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/66605#M12857</link>
      <description>Not sure it works that way, but you can try it on R80.30 or R80.20 JHF 117 or later.</description>
      <pubDate>Tue, 05 Nov 2019 15:07:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/66605#M12857</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-05T15:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is there SNI support for inbound HTTPS inspection in R80.20?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/66650#M12858</link>
      <description>&lt;P&gt;I checked with our experts in R&amp;amp;D and, provided you are on R80.30, you should be able to achieve it.&lt;BR /&gt;It should also work on R80.20 JHF 117 and above, but not sure it was tested there.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can import the certificates into the gateway, create different custom application with each URL, and create an HTTPS Inspection rule with different certificate for each custom certificate similar to the following:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image001.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2968iCDD8B93CB835E30B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image001.png" alt="image001.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 07:21:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-SNI-support-for-inbound-HTTPS-inspection-in-R80-20/m-p/66650#M12858</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-06T07:21:37Z</dc:date>
    </item>
  </channel>
</rss>

