<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS Inspection of Traffic Flow - HTTPS, FIREWALL AND IPS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-of-Traffic-Flow-HTTPS-FIREWALL-AND-IPS/m-p/71026#M13338</link>
    <description>&lt;P&gt;We have enabled HTTPS inspection covering IPS, IDS, antibot and antivirus. What should be appearing first on the traffic rule in the firewall. Because I normally see https inspection then firewall then IDS. Could you kindly provide an idea on how to carefully analyze these. Which blade should be first appearing on the traffic thats my concern.&lt;/P&gt;</description>
    <pubDate>Sat, 21 Dec 2019 12:51:10 GMT</pubDate>
    <dc:creator>keydee</dc:creator>
    <dc:date>2019-12-21T12:51:10Z</dc:date>
    <item>
      <title>HTTPS Inspection of Traffic Flow - HTTPS, FIREWALL AND IPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-of-Traffic-Flow-HTTPS-FIREWALL-AND-IPS/m-p/71026#M13338</link>
      <description>&lt;P&gt;We have enabled HTTPS inspection covering IPS, IDS, antibot and antivirus. What should be appearing first on the traffic rule in the firewall. Because I normally see https inspection then firewall then IDS. Could you kindly provide an idea on how to carefully analyze these. Which blade should be first appearing on the traffic thats my concern.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2019 12:51:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-of-Traffic-Flow-HTTPS-FIREWALL-AND-IPS/m-p/71026#M13338</guid>
      <dc:creator>keydee</dc:creator>
      <dc:date>2019-12-21T12:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection of Traffic Flow - HTTPS, FIREWALL AND IPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-of-Traffic-Flow-HTTPS-FIREWALL-AND-IPS/m-p/71038#M13339</link>
      <description>In general you can expect Access Control logs (firewall, VPN, App Control, URL Filtering) to come up before Threat Prevention logs.&lt;BR /&gt;HTTPS Inspection may be required before either Access Control or Threat Prevention makes sense, so these logs may appear before the others.&lt;BR /&gt;There are circumstances where it might vary from this slightly.&lt;BR /&gt;If you have a specific concern, a concrete example from your logs would be helpful.</description>
      <pubDate>Sat, 21 Dec 2019 20:18:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-of-Traffic-Flow-HTTPS-FIREWALL-AND-IPS/m-p/71038#M13339</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-21T20:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection of Traffic Flow - HTTPS, FIREWALL AND IPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-of-Traffic-Flow-HTTPS-FIREWALL-AND-IPS/m-p/71044#M13340</link>
      <description>&lt;DIV id="tinyMceEditorHeikoAnkenbrand_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy Matchimg.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3831i216FC28A7A27EA76/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy Matchimg.JPG" alt="Policy Matchimg.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;Picture is from &lt;A href="https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/member-exclusives/424/2/CheckMatest_HTTPS_Inspection_Best_Practices_v3.pptx" target="_self"&gt;Slides&lt;/A&gt; in article:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Access-Control-Products/HTTPS-Inspection-Best-Practices-TechTalk-Video-Slides-and-Q-amp/m-p/71017#M1195" target="_self"&gt;HTTPS Inspection Best Practices TechTalk: Video, Slides, and Q&amp;amp;A&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;PS: Log entries should appear in a similar order.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2019 21:13:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-of-Traffic-Flow-HTTPS-FIREWALL-AND-IPS/m-p/71044#M13340</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-12-21T21:13:09Z</dc:date>
    </item>
  </channel>
</rss>

