<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS inspection of internal private IP traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/117621#M16624</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;We have an issue where internal HTTPS applications are being inspected using HTTPS interception&lt;/P&gt;&lt;P&gt;My understanding was that for outbound inspection only applications accessed through an interface marked as "External" etc would be intercepted.&amp;nbsp; I remember reading this a long time ago in some Checkpoint documentation, but I am failing to find this reference again.&lt;/P&gt;&lt;P&gt;I am interested in locating a reference document for HTTPS inspection where I hope to fins&amp;nbsp;&lt;SPAN&gt;a description of what traffic is HTTPS inspection applied to.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I is strange as this issue with Internal applications being using HTTPS interception exists only on one security gateway and none of the other Security gateway clusters are showing this behaviour.&amp;nbsp; The HTTPS inspection policy only has "Bypass" rules with the generic "inspection" rule for everything else at the end of the policy.&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
    <pubDate>Tue, 04 May 2021 09:44:50 GMT</pubDate>
    <dc:creator>Michael_Horne</dc:creator>
    <dc:date>2021-05-04T09:44:50Z</dc:date>
    <item>
      <title>HTTPS inspection of internal private IP traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/117621#M16624</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;We have an issue where internal HTTPS applications are being inspected using HTTPS interception&lt;/P&gt;&lt;P&gt;My understanding was that for outbound inspection only applications accessed through an interface marked as "External" etc would be intercepted.&amp;nbsp; I remember reading this a long time ago in some Checkpoint documentation, but I am failing to find this reference again.&lt;/P&gt;&lt;P&gt;I am interested in locating a reference document for HTTPS inspection where I hope to fins&amp;nbsp;&lt;SPAN&gt;a description of what traffic is HTTPS inspection applied to.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I is strange as this issue with Internal applications being using HTTPS interception exists only on one security gateway and none of the other Security gateway clusters are showing this behaviour.&amp;nbsp; The HTTPS inspection policy only has "Bypass" rules with the generic "inspection" rule for everything else at the end of the policy.&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 09:44:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/117621#M16624</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2021-05-04T09:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection of internal private IP traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/117628#M16626</link>
      <description>&lt;P&gt;Your understanding is incorrect. Any traffic matching your HTTPS inspection rulebase will be inspected.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Now, you are most probably referring to "Internet" object used as destination by default for outbound HTTPSi rules. Mind you, Internet object is interpreted by GW as everything but internal IP addresses defined by topology. In many cases that would include DMZ networks that are NAT-ed, or any other internal addresses that do not appear in the GW topology.&lt;BR /&gt;&lt;BR /&gt;If you are using ANY and not Internet object, then any HTTPSi traffic crossing GW will be inspected.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The solution here is very simple: put bypass rules for any traffic you do not want to inspect, and also use exclusively web services in HTTPSi rulebase.&lt;BR /&gt;&lt;BR /&gt;There is a few discussions in the community for that matter, including HTTPSi best practice techtalk, with video recording.&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 10:24:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/117628#M16626</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-04T10:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection of internal private IP traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/117633#M16628</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for the feedback.&amp;nbsp; &amp;nbsp;I should be asking instead not why 1 gateway is inspecting the internal applications, but why the other 19+ gateways are not, as they are all sharing the same default HTTPS inspection rule with the Internet object as destination.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess the crucial part is "&lt;SPAN&gt;internal IP addresses defined by topology", but since all the 20 gateways are accessing the application over an interface with a standard Topology definition "Internet (External)", I am still confused as to the behaviour. All gateways (except&amp;nbsp;the one where the application&amp;nbsp;is hosted), should all not have the internal IPs in the topology.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Investigations continue ...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 11:58:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/117633#M16628</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2021-05-04T11:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection of internal private IP traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/117639#M16629</link>
      <description>&lt;P&gt;Let's be more pragmatic. How does your inspection policy look like?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 12:22:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/117639#M16629</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-04T12:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection of internal private IP traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/118050#M16708</link>
      <description>&lt;P&gt;The information you gave was helpful as it seems that the issue was with the topology for the relevant interface.&lt;/P&gt;&lt;P&gt;I changed the external facing interface from the "red" Internet (External) topology setting to the "green" Internet (External) topology setting and reports back from the end users confirm they no longer have issues with the applications.&lt;/P&gt;&lt;P&gt;I&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Topology" style="width: 564px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11655iD7C8991C96F31584/image-size/large?v=v2&amp;amp;px=999" role="button" title="topology.png" alt="Topology" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Topology&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The interesting question is what is the difference between these tow topology settings as both are Internet (External).&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 09:44:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-of-internal-private-IP-traffic/m-p/118050#M16708</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2021-05-10T09:44:40Z</dc:date>
    </item>
  </channel>
</rss>

