<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection - Performace issues at first page request / VSX in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163420#M29181</link>
    <description>&lt;P&gt;- Yes, CAs are fine&lt;/P&gt;&lt;P&gt;- Internet access works properly, but we get CRL detect messages in the logs (details below)&lt;BR /&gt;&lt;BR /&gt;- Policy is simple with a few rules:&amp;nbsp;&lt;SPAN&gt;Bypass by source, destination, URL/Category, "CP-recommended services" and afterwards an "inspect any"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- R81.10 T55&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding CRL: We saw constant detects, mainly to Microsoft services and I tried to trace that down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe that this issue is because of an error in the certificate of MS itself -&amp;gt; the CRL link seems to contain a space at the end, therefore CP fails to access it:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18566i596F1491DA9B8E23/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 530px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18568i36CDE39DF09C3D42/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 978px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18567i4DC0A0ABF2D0DC5A/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is the issue that occurs constantly, since the service seems to be accessed by Windows constantly. Otherwise there are only a few logs due to expired certs or similar.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Nov 2022 16:31:39 GMT</pubDate>
    <dc:creator>xiro</dc:creator>
    <dc:date>2022-11-28T16:31:39Z</dc:date>
    <item>
      <title>HTTPS Inspection - Performace issues at first page request / VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163355#M29152</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a VSX implementation with 5 different VS, and for one of them we just enabled HTTPS-Inspection.&lt;/P&gt;&lt;P&gt;Unfortunately the users are complaining constantly about performance &amp;amp; sites that are not working properly. We have bypassed already dozens of sites, (even low/very low category), but it won't get better.&lt;/P&gt;&lt;P&gt;Besides sites that mitigate Inspection by design (banking), one main issue is that the first access to a page is extremely slow (e.g. apple.com). Afterwards, all other requests work fine. In older versions we had similar issues that we could fix with mechanisms like "probe bypass". But our VSX is running on 81.10, therefore probe bypass should be irrelevant (since 80.30).&lt;/P&gt;&lt;P&gt;The Site Categorization mode is set to "Hold", but despite changing it to "Background" (installing DB, installing VS-policy, installing VS0-policy), the changes are not having any effect on the behavior. Fail Mode is "fail-open".&lt;/P&gt;&lt;P&gt;&amp;nbsp;The GWs are bored to death (10% CPU load during business hours).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what else we could check or try to improve the user experience?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 12:53:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163355#M29152</guid>
      <dc:creator>xiro</dc:creator>
      <dc:date>2022-11-28T12:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Performace issues at first page request / VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163359#M29153</link>
      <description>&lt;P&gt;Some questions for context:&lt;/P&gt;
&lt;P&gt;Have you checked if the trusted CA list is up to date?&lt;/P&gt;
&lt;P&gt;Check Internet access works for CRL checks?&lt;/P&gt;
&lt;P&gt;How is the HTTPS inspection policy structured?&lt;/P&gt;
&lt;P&gt;Which JHF is the cluster currently installed with?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 15:22:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163359#M29153</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-28T15:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Performace issues at first page request / VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163364#M29155</link>
      <description>&lt;P&gt;I would suggest checking internet connectivity from the VSX cluster, including VS0. Check that DNS is working, and connections from your VSX GWs to Internet are not blocked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 13:37:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163364#M29155</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-28T13:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Performace issues at first page request / VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163398#M29166</link>
      <description>&lt;P&gt;the vsx is connected directly to the internet (nothing in between), all connections and checks are fine...&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 15:40:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163398#M29166</guid>
      <dc:creator>xiro</dc:creator>
      <dc:date>2022-11-28T15:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Performace issues at first page request / VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163420#M29181</link>
      <description>&lt;P&gt;- Yes, CAs are fine&lt;/P&gt;&lt;P&gt;- Internet access works properly, but we get CRL detect messages in the logs (details below)&lt;BR /&gt;&lt;BR /&gt;- Policy is simple with a few rules:&amp;nbsp;&lt;SPAN&gt;Bypass by source, destination, URL/Category, "CP-recommended services" and afterwards an "inspect any"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- R81.10 T55&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding CRL: We saw constant detects, mainly to Microsoft services and I tried to trace that down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe that this issue is because of an error in the certificate of MS itself -&amp;gt; the CRL link seems to contain a space at the end, therefore CP fails to access it:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18566i596F1491DA9B8E23/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 530px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18568i36CDE39DF09C3D42/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 978px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18567i4DC0A0ABF2D0DC5A/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is the issue that occurs constantly, since the service seems to be accessed by Windows constantly. Otherwise there are only a few logs due to expired certs or similar.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 16:31:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163420#M29181</guid>
      <dc:creator>xiro</dc:creator>
      <dc:date>2022-11-28T16:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Performace issues at first page request / VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163436#M29182</link>
      <description>&lt;P&gt;Since we check the certificate as part of HTTPS Inspection (including the CRL), perhaps the issues with this are creating the delays?&lt;BR /&gt;I know you can disable CRL checking in HTTPS Inspection, which isn't necessarily recommended.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 01:12:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163436#M29182</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-29T01:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Performace issues at first page request / VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163478#M29190</link>
      <description>&lt;P&gt;Then, if you cannot find any obvious issue, please take it with TAC.&lt;BR /&gt;&lt;BR /&gt;According to your description, it sounds like a connectivity issue causing a delay with certificate validation, but it might be also something else. Aks support to look into this.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 09:27:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163478#M29190</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-29T09:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Performace issues at first page request / VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163488#M29193</link>
      <description>&lt;P&gt;Regarding the HTTPS Inspection policy structure the following may be helpful for you:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/HTTPS-Inspection-Setup/m-p/127750/highlight/true#M27820" target="_blank"&gt;https://community.checkpoint.com/t5/Management/HTTPS-Inspection-Setup/m-p/127750/highlight/true#M27820&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 09:44:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performace-issues-at-first-page-request-VSX/m-p/163488#M29193</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-29T09:44:17Z</dc:date>
    </item>
  </channel>
</rss>

