<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sandboxing http/https traffics with web proxy(bluecoat) in place in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6065#M14042</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Norbert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wish to implement the sandblast appliance to intercept https traffic for Sandboxing. I would like  to deploy the Sandblast appliance after proxy towards internet and using fail open card.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Biju Nair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Sep 2017 19:28:51 GMT</pubDate>
    <dc:creator>Biju_Nair</dc:creator>
    <dc:date>2017-09-07T19:28:51Z</dc:date>
    <item>
      <title>Sandboxing http/https traffics with web proxy(bluecoat) in place</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6062#M14039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, In a scenario with 3rd party web proxy(bluecoat) in place, how would the https traffic be handled by sandblast appliance. Considering bluecoat itself is doing https inspection first.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2017 14:13:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6062#M14039</guid>
      <dc:creator>Biju_Nair</dc:creator>
      <dc:date>2017-09-07T14:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Sandboxing http/https traffics with web proxy(bluecoat) in place</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6063#M14040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is not much information, how you want (or have) implemented the Sandblast appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So just to keep it general:&lt;/P&gt;&lt;P&gt;If you want the https traffic to be inspected there has to be ssl-inspection active. Detail configuration for that depends on the implementation (sandblast before proxy or after).&lt;/P&gt;&lt;P&gt;Other way would be to use ICAP-client on proxy to speak with ICAP-server on Sandblast appliance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2017 14:40:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6063#M14040</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2017-09-07T14:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sandboxing http/https traffics with web proxy(bluecoat) in place</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6064#M14041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a look at&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk111306 and install JHF 284 or newer which includes the ICAP server feature.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;HTH,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Christian&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2017 15:27:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6064#M14041</guid>
      <dc:creator>Christian_Sandb</dc:creator>
      <dc:date>2017-09-07T15:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sandboxing http/https traffics with web proxy(bluecoat) in place</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6065#M14042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Norbert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wish to implement the sandblast appliance to intercept https traffic for Sandboxing. I would like  to deploy the Sandblast appliance after proxy towards internet and using fail open card.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Biju Nair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2017 19:28:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6065#M14042</guid>
      <dc:creator>Biju_Nair</dc:creator>
      <dc:date>2017-09-07T19:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Sandboxing http/https traffics with web proxy(bluecoat) in place</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6066#M14043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmmm. So you want two devices to break open SSL traffic independently?&lt;/P&gt;&lt;P&gt;This is the sort of stuff I would advise if you want nightmares.&lt;/P&gt;&lt;P&gt;It will be slow to the users and the likely hood you will get into negotiate trouble is big.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:27:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6066#M14043</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-09-08T07:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Sandboxing http/https traffics with web proxy(bluecoat) in place</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6067#M14044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can only say that Hugo is right here and ICAP is the much better way to move forward!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:43:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6067#M14044</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2017-09-08T07:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Sandboxing http/https traffics with web proxy(bluecoat) in place</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6068#M14045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hugo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Norbert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we plan for ICAP then the proxy will act as a ICAP client and will send the traffic to sandblast(ICAP server).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But how would the https traffic work in ICAP scenario. Will proxy send the decrypted packet to sandblast and wait for verdict from sandblast by holding the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Biju Nair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 09:53:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6068#M14045</guid>
      <dc:creator>Biju_Nair</dc:creator>
      <dc:date>2017-09-08T09:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sandboxing http/https traffics with web proxy(bluecoat) in place</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6069#M14046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's the basic idea.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 21:16:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6069#M14046</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-08T21:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Sandboxing http/https traffics with web proxy(bluecoat) in place</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6070#M14047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition this helps getting you started on the BC side:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://support.symantec.com/en_US/article.DOC9825.html" title="https://support.symantec.com/en_US/article.DOC9825.html"&gt;ProxySG ICAP Integration&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards Thomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Sep 2017 07:20:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandboxing-http-https-traffics-with-web-proxy-bluecoat-in-place/m-p/6070#M14047</guid>
      <dc:creator>Thomas_Werner</dc:creator>
      <dc:date>2017-09-14T07:20:05Z</dc:date>
    </item>
  </channel>
</rss>

