<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint URLF Block Page Certificate in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/147973#M23596</link>
    <description>&lt;P&gt;You can import &amp;nbsp;a certificate enrolled from your internal CA to the usercheck page of the gateway properties. Your clients should trust these CA. If you‘re using the default certificate, your clients have to trust your internal Check Point CA of the managementserver. You can export the public certificate from the managementserver.&lt;/P&gt;</description>
    <pubDate>Thu, 05 May 2022 19:57:36 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2022-05-05T19:57:36Z</dc:date>
    <item>
      <title>Checkpoint URLF Block Page Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/147967#M23594</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have enabled&amp;nbsp;Checkpoint URLF with HTTPS Inspection enabled. All is working fine, except I am getting cert trust issues with the block page. (R80.40)&lt;/P&gt;&lt;P&gt;Can anyone advise how I export this block page cert so I can trust it in users browsers? Or if there is some other guidance?&lt;/P&gt;&lt;P&gt;Also, is enabling UserCheck required in order to serve the block page, or is that something different? I have that enabled.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 18:37:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/147967#M23594</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-05-05T18:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint URLF Block Page Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/147973#M23596</link>
      <description>&lt;P&gt;You can import &amp;nbsp;a certificate enrolled from your internal CA to the usercheck page of the gateway properties. Your clients should trust these CA. If you‘re using the default certificate, your clients have to trust your internal Check Point CA of the managementserver. You can export the public certificate from the managementserver.&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 19:57:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/147973#M23596</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-05-05T19:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint URLF Block Page Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148001#M23597</link>
      <description>&lt;P&gt;In addition to what Wolfgang state .... from my notes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We require an SSL certificate on the GW's as the page presented with the BLOCK message, is HTTPS and is using the Platform Portal (as it seems) .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They say to follow :&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97648" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97648&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But it’s better to follow :&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69660" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69660&lt;/A&gt;&lt;/P&gt;&lt;P&gt;(as I've &lt;A href="onenote:#Cert%20-%20right%20process&amp;amp;section-id={6E6CB16C-9011-46F0-8E18-0214F540E5FE}&amp;amp;page-id={3A72BE78-2F2B-4F7E-917A-5B821F2D9F84}&amp;amp;end&amp;amp;base-path=https://alvteams.alv.autoliv.int/sites/alvitnetwork/SiteAssets/Global%20Network%20Team%20Notebook/Firewall%20Services/General.one" target="_blank" rel="noopener"&gt;use it previously&lt;/A&gt; )&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 05:24:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148001#M23597</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-05-06T05:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint URLF Block Page Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148010#M23601</link>
      <description>&lt;P&gt;Thanks Wolfgang, is there a simple way to export this certificate from the SMS GUI?&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 08:01:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148010#M23601</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-05-06T08:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint URLF Block Page Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148011#M23602</link>
      <description>&lt;P&gt;Cheers Sorin, seems a bit confaluted. Id like to just extract whatever cert is being currently served for block page.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 08:02:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148011#M23602</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-05-06T08:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint URLF Block Page Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148015#M23604</link>
      <description>&lt;P&gt;Could I extrapolate from the below message that one must use a self signed cert to avoid errors i.e. the auto-generated cert is not extractable?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-05-06 at 09.03.49.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16401iFBA7A072DDDE03F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-05-06 at 09.03.49.png" alt="Screenshot 2022-05-06 at 09.03.49.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 08:07:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148015#M23604</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-05-06T08:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint URLF Block Page Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148024#M23611</link>
      <description>&lt;P&gt;Now I got it, your certificate error is shown to the end-user when he is redirected to the Block page - that is served by the GW Custer .&lt;/P&gt;&lt;P&gt;You can generate a certificate (signed by the same CA that you used to delegate HTTPS Inspection) and import it into the UserCheck .&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 09:24:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148024#M23611</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-05-06T09:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint URLF Block Page Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148027#M23613</link>
      <description>&lt;P&gt;Yes Sorin, serving of blockpage shows connection error, or client not trusting the cert.&lt;/P&gt;&lt;P&gt;So, for clarification, I must generate a self signed cert to avoid errors? Is there definitely no way to export whatever cert Checkpoint is providing by default?&amp;nbsp; - I find this surprising.&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 09:54:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148027#M23613</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-05-06T09:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint URLF Block Page Certificate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148028#M23614</link>
      <description>&lt;P&gt;For sure you can export it, is the same you get when accessing the &lt;SPAN&gt;UserCheck&amp;nbsp;portal It's not an on-the-fly generated one.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After that you will need to et it on all the clients in trusted certs, therefore my recommendation&amp;nbsp;is to look for a centralized CA/certificate solution, then you just need to trust the Root CA and all the rest will follow.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 11:11:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-URLF-Block-Page-Certificate/m-p/148028#M23614</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-05-06T11:11:36Z</dc:date>
    </item>
  </channel>
</rss>

