<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection implemented, only working in Safari browser for MAC in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140569#M26971</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21842"&gt;@Ryan_Coots&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you haven't already, you could enable the SSL/TLS signatures in Detect mode to see which version is being used on your connections:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tls-ssl-ips.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15251i9DC60911069FEE77/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tls-ssl-ips.PNG" alt="tls-ssl-ips.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You can also set the minimum/maximum SSL/TLS versions in GUIDBedit. The update from Heiko Ankenbrand details how to do this (if necessary):&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/td-p/70338" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/td-p/70338&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Feb 2022 21:04:59 GMT</pubDate>
    <dc:creator>AaronCP</dc:creator>
    <dc:date>2022-02-04T21:04:59Z</dc:date>
    <item>
      <title>HTTPS Inspection implemented, only working in Safari browser for MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140542#M26968</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;We are on R80.40 JFA 125. I have implemented https inspection, generated a certificate off of Smartconsole, downloaded and installed that on a few test machines, and built a ruleset. The bypass rules are working for banking/medicare, and everyone I don't want inspection for, but the inspection rule results in the attached error message for any website from Edge, Firefox, and Chrome on both PCs and Macs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only space it is working in, is safari on a mac. Does anyone have any idea why https inspection is not working for all of the other browsers? I have read the common SKs, and have a ticket in with support, they suggested a hotfix wrapper which we installed with no change. We are escalating it as we speak, but wanted to reach out to the group in case anyone has seen this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we generated the certificate from SmartDashboard, we then exported it, and put it in the trusted certificate root authorities folder on our PCs and in the system keychain on the Mac.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all!&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 17:30:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140542#M26968</guid>
      <dc:creator>Ryan_Coots</dc:creator>
      <dc:date>2022-02-04T17:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection implemented, only working in Safari browser for MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140545#M26969</link>
      <description>&lt;P&gt;The client doesn't like something about the TLS negotiation. Get a packet capture and see what algorithms are proposed by each end.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 18:21:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140545#M26969</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-02-04T18:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection implemented, only working in Safari browser for MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140564#M26970</link>
      <description>&lt;P&gt;I will give that a try, is there a way to tweak what CheckPoint proposes if I find a discrepancy, so that I don't have to tweak anything on each individual client?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 20:02:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140564#M26970</guid>
      <dc:creator>Ryan_Coots</dc:creator>
      <dc:date>2022-02-04T20:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection implemented, only working in Safari browser for MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140569#M26971</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21842"&gt;@Ryan_Coots&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you haven't already, you could enable the SSL/TLS signatures in Detect mode to see which version is being used on your connections:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tls-ssl-ips.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15251i9DC60911069FEE77/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tls-ssl-ips.PNG" alt="tls-ssl-ips.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You can also set the minimum/maximum SSL/TLS versions in GUIDBedit. The update from Heiko Ankenbrand details how to do this (if necessary):&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/td-p/70338" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/td-p/70338&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 21:04:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140569#M26971</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-02-04T21:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection implemented, only working in Safari browser for MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140577#M26972</link>
      <description>&lt;P&gt;Since I spent I can't even count how many hours with TAC troubleshooting https inspection issues, I will list few things I always found to be a problem.&lt;/P&gt;
&lt;P&gt;-when you see error like one you attached, first thing I always do is check pop monitor user command to see if access roles are matched (this ONLY if you use identity awareness)&lt;/P&gt;
&lt;P&gt;-if you don't use IA blade, regardless, make sure the inspection rules have block user check enabled in the action column&lt;/P&gt;
&lt;P&gt;-verify that trusted cert list is updated and valid&lt;/P&gt;
&lt;P&gt;-in dashboard, make sure that you filter logs for https inspection blade and observe the message&lt;/P&gt;
&lt;P&gt;Those are just some basic things to look at. Be free to message me privately if you need help, Im sure I could help you out with this,&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 22:18:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140577#M26972</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-04T22:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection implemented, only working in Safari browser for MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140793#M26973</link>
      <description>&lt;P&gt;Thanks for the info, we do not use IA, so I am looking into the Block User Check action now and in the https inspection rulebase, all I have the option for is Inspect/Bypass.&lt;/P&gt;&lt;P&gt;Trusted cert list is updated, and the logs look good as best I can tell. They appear to be inspected, just not functional client side.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 17:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140793#M26973</guid>
      <dc:creator>Ryan_Coots</dc:creator>
      <dc:date>2022-02-07T17:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection implemented, only working in Safari browser for MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140812#M26974</link>
      <description>&lt;P&gt;Ok, fair enough. Regardless for the fact you don't use IA blade, which is totally fine in this case, maybe do fw monitor when client gets this problem, so then we can filter for tls lines in Wireshark. Either way, you should see block notification user check page, 100%. There is one kernel parameter I found to sometimes cause this, but I don't want to mention it here, as I got in trouble for it before : )&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 22:56:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-implemented-only-working-in-Safari-browser-for/m-p/140812#M26974</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-07T22:56:14Z</dc:date>
    </item>
  </channel>
</rss>

