<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174428#M31759</link>
    <description>&lt;P&gt;Interesting...I tested this today in my R81.20 lab and when gateway is configured as non-transparent proxy, the https bypass rules worked just fine.&lt;/P&gt;</description>
    <pubDate>Sat, 11 Mar 2023 02:55:34 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-03-11T02:55:34Z</dc:date>
    <item>
      <title>HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174226#M31709</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know whether there is a way to configure HTTPS Inspection Bypass for a certain domain (e.g. google.com) when using Security Gateway (in our case a virtual system / VSX environment) as HTTPS Proxy (non-transparent)!?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;When configuring a bypass rule in HTTPS Inspection Policy with Security Gateway / Virtual System as Destination then it works, but then all relevant traffic will bypass HTTPS Inspection (for traffic from client to Security Gateway / HTTPS Proxy) and that's not desired configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R81.10 JHF Take 79 is installed on the Security Gateways and Management Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help!&lt;BR /&gt;&lt;BR /&gt;Best Regards&lt;/P&gt;&lt;P&gt;Nenad&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 11:52:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174226#M31709</guid>
      <dc:creator>Nenad_D</dc:creator>
      <dc:date>2023-03-09T11:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174248#M31713</link>
      <description>&lt;P&gt;I remember testing this back in R77 versions, but not in R80+, so trying to remember how I made it work. I know I had to make some modifications on the gateway settings in smart console...can you send a screenshot of how https proxy tab is configured on gateway object?&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 13:53:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174248#M31713</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-09T13:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174252#M31714</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;here a screenshot of the HTTP Proxy tab on the Security Gateway / Virtual System object:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-03-09 15_18_40-Admin_Desktop_DELIN ITMGMT Server - Desktop Viewer.png" style="width: 745px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20011iF4DFFE2D58398425/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-03-09 15_18_40-Admin_Desktop_DELIN ITMGMT Server - Desktop Viewer.png" alt="2023-03-09 15_18_40-Admin_Desktop_DELIN ITMGMT Server - Desktop Viewer.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help!&lt;BR /&gt;&lt;BR /&gt;Best Regards&lt;/P&gt;&lt;P&gt;Nenad&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 14:23:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174252#M31714</guid>
      <dc:creator>Nenad_D</dc:creator>
      <dc:date>2023-03-09T14:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174256#M31716</link>
      <description>&lt;P&gt;No problem, thank you. I will have to check and see if I had to modify the actual ports at the bottom, so give me some time. Apologies, this was probably more than 7 years ago, so will need to see if I still have details on how I did this.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 15:03:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174256#M31716</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-09T15:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174281#M31722</link>
      <description>&lt;P&gt;Ok, just made it work by modifying below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20014iF109A78902294584/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 18:32:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174281#M31722</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-09T18:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174326#M31731</link>
      <description>&lt;P&gt;Hi Andy,&lt;BR /&gt;&lt;BR /&gt;thanks very much for sharing the information.&lt;/P&gt;&lt;P&gt;But I think I didn't get it how that will help to configure certain HTTPS Inspection Bypass rules when using the proxy.&lt;BR /&gt;Anything else I need to configure?&lt;BR /&gt;Could you please explain?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance!&lt;BR /&gt;&lt;BR /&gt;Best Regards&lt;/P&gt;&lt;P&gt;Nenad&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 08:38:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174326#M31731</guid>
      <dc:creator>Nenad_D</dc:creator>
      <dc:date>2023-03-10T08:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174349#M31734</link>
      <description>&lt;P&gt;From notes I have, that was the only change I had to make on CP side. Can you send a screenshot of bypass rule(s)?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 12:18:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174349#M31734</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-10T12:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174385#M31747</link>
      <description>&lt;P&gt;Hi Andy,&lt;BR /&gt;&lt;BR /&gt;a common bypass rule looks like the following:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-03-10 16_15_14-Admin_Desktop_DELIN ITMGMT Server - Desktop Viewer.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20026iA19B2B472A749582/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-03-10 16_15_14-Admin_Desktop_DELIN ITMGMT Server - Desktop Viewer.png" alt="2023-03-10 16_15_14-Admin_Desktop_DELIN ITMGMT Server - Desktop Viewer.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-03-10 16_16_33-Admin_Desktop_DELIN ITMGMT Server - Desktop Viewer.png" style="width: 238px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20027iC5F3F0F7DC4AE3C6/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-03-10 16_16_33-Admin_Desktop_DELIN ITMGMT Server - Desktop Viewer.png" alt="2023-03-10 16_16_33-Admin_Desktop_DELIN ITMGMT Server - Desktop Viewer.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I will check whether it works with proxy settings you mentioned.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;Best Regards&lt;BR /&gt;Nenad&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 15:21:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174385#M31747</guid>
      <dc:creator>Nenad_D</dc:creator>
      <dc:date>2023-03-10T15:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174386#M31748</link>
      <description>&lt;P&gt;Sounds good, yea, bypass rule looks right to me. If it still does not work, I will dig further and see if there was anything else I had to change.&lt;/P&gt;
&lt;P&gt;ANdy&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 15:24:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174386#M31748</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-10T15:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174418#M31755</link>
      <description>&lt;P&gt;HTTPS Inspection always sees the gateway as the destination when non-transparent proxy mode is used.&lt;BR /&gt;As such, the HTTPS Inspection policy will never match another destination.&lt;BR /&gt;This is expected behavior.&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108706" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108706&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2023 00:15:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174418#M31755</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-11T00:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Bypass when using Security Gateway as HTTPS Proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174428#M31759</link>
      <description>&lt;P&gt;Interesting...I tested this today in my R81.20 lab and when gateway is configured as non-transparent proxy, the https bypass rules worked just fine.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2023 02:55:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Bypass-when-using-Security-Gateway-as-HTTPS/m-p/174428#M31759</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-11T02:55:34Z</dc:date>
    </item>
  </channel>
</rss>

