<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Https inspection query on Cloudguard IaaS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116855#M16486</link>
    <description>&lt;P&gt;The traffic will be HTTP traffic if it's coming from the load balancer.&amp;nbsp;&lt;BR /&gt;Whatever blades you have activated with appropriate policies will apply to the traffic.&lt;BR /&gt;This should be clearly visible in the Logs and Monitoring (or SmartView).&lt;/P&gt;</description>
    <pubDate>Mon, 26 Apr 2021 05:44:32 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-04-26T05:44:32Z</dc:date>
    <item>
      <title>Https inspection query on Cloudguard IaaS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116660#M16456</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have deployed autoscale security gateway on AWS cloud only for Northbound traffic to protect web application hosted in AWS customer account.&lt;/P&gt;&lt;P&gt;All application are publicly published and can be access from Internet.&lt;/P&gt;&lt;P&gt;Below is the traffic flow:&lt;/P&gt;&lt;P&gt;User access web application from internet---&amp;gt;traffic came to route53 and resolved in load balancer Ip adddress---&amp;gt;&amp;gt;when external load received the traffic and do the Ssl termination and sent the traffic to target group----&amp;gt;&amp;gt;Target Group is Cloudguard IaaS firewall-----&amp;gt;Internal LB---&amp;gt;application hosted server.&lt;/P&gt;&lt;P&gt;My query is here that when External load balancer doing the ssl termination and sent the decrypted to Cloudguard IaaS.&lt;/P&gt;&lt;P&gt;Is it require to do https inspection on Cloudguard IaaS for received decrypted traffic from external LB?&lt;/P&gt;&lt;P&gt;If I am not doing https inspection because received traffic from external LB is already decrypted. Will my enabled blade on firewall do inspect of these traffic.&lt;/P&gt;&lt;P&gt;Please guide me to do correct deployment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 15:59:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116660#M16456</guid>
      <dc:creator>avi3383</dc:creator>
      <dc:date>2021-04-22T15:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Https inspection query on Cloudguard IaaS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116843#M16484</link>
      <description>&lt;P&gt;If the gateway is seeing only unencrypted traffic, then you don't need to run HTTPS Inspection at all.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 04:33:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116843#M16484</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-26T04:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Https inspection query on Cloudguard IaaS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116848#M16485</link>
      <description>&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;is there any way to identify unencrypted traffic logs? Please guide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 05:19:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116848#M16485</guid>
      <dc:creator>avi3383</dc:creator>
      <dc:date>2021-04-26T05:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Https inspection query on Cloudguard IaaS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116855#M16486</link>
      <description>&lt;P&gt;The traffic will be HTTP traffic if it's coming from the load balancer.&amp;nbsp;&lt;BR /&gt;Whatever blades you have activated with appropriate policies will apply to the traffic.&lt;BR /&gt;This should be clearly visible in the Logs and Monitoring (or SmartView).&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 05:44:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116855#M16486</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-26T05:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Https inspection query on Cloudguard IaaS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116860#M16488</link>
      <description>&lt;P&gt;Can you confirm below logs are http logs...these are coming from LB and Https termination are enabled on LB.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 06:43:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116860#M16488</guid>
      <dc:creator>avi3383</dc:creator>
      <dc:date>2021-04-26T06:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: Https inspection query on Cloudguard IaaS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116864#M16490</link>
      <description>&lt;P&gt;If it were straight HTTP, the service would say...HTTP.&lt;BR /&gt;There are a lot of things in those logs that say TLS, which is most likely encrypted.&lt;BR /&gt;There are things that say TCP also, which is probably not encrypted.&lt;BR /&gt;To confirm what it is, you'd probably have to run a tcpdump to see what the actual traffic looks like.&lt;/P&gt;
&lt;P&gt;Note that HTTPS Inspection is generally only done with HTTPS traffic on one of the standard ports.&lt;BR /&gt;It doesn't work with TLS traffic in general.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 06:51:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Https-inspection-query-on-Cloudguard-IaaS/m-p/116864#M16490</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-26T06:51:16Z</dc:date>
    </item>
  </channel>
</rss>

