<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection Action:Error in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182226#M33403</link>
    <description>&lt;P&gt;The error states that the GW cannot validate the server certificate. If it only happens to some of the connections to the same server and not all, look if you have any intermittent connectivity failures on that GW. Also, it might be that the destination IP hosts multiple web servers, some of them with bad certificates.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 May 2023 05:58:55 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-05-26T05:58:55Z</dc:date>
    <item>
      <title>HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182213#M33396</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Hello, I would like to know if anyone here has been presented with this error?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Reviewing logs I have this error towards a specific destination, but what seems strange to me that this error appears depends on the Source because with some other sources the error does not appear towards the destination that presents the problem.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;As additional information, both the source and destination segments have bypass rules in HTTPS INSPECTION.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Thanks a lot for the help.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;............................................................................................................................................................................&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Id Generated By Indexer:&amp;nbsp;&amp;nbsp;&amp;nbsp; false&lt;BR /&gt;First:&amp;nbsp;&amp;nbsp;&amp;nbsp; true&lt;BR /&gt;Sequencenum:&amp;nbsp;&amp;nbsp;&amp;nbsp; 205&lt;BR /&gt;HTTPS Validation:&amp;nbsp;&amp;nbsp;&amp;nbsp; The probe detected that this destination cannot be inspected and its identity cannot be verified due to a TLS alert (TLS alert: bad_certificate)&lt;BR /&gt;Description:&amp;nbsp;&amp;nbsp;&amp;nbsp; Bypassing request as configured in engine settings of HTTPS Inspection&lt;BR /&gt;Source:&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x&lt;BR /&gt;Source Port:&amp;nbsp;&amp;nbsp;&amp;nbsp; 60374&lt;BR /&gt;Destination:&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x&lt;BR /&gt;Destination Port:&amp;nbsp;&amp;nbsp;&amp;nbsp; 443&lt;BR /&gt;IP Protocol:&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP (6)&lt;BR /&gt;Action:&amp;nbsp;&amp;nbsp;&amp;nbsp; Bypass&lt;BR /&gt;Type:&amp;nbsp;&amp;nbsp;&amp;nbsp; Log&lt;BR /&gt;Policy Name:&amp;nbsp; &amp;nbsp;YYYY&lt;BR /&gt;Policy Management:&amp;nbsp;&amp;nbsp;&amp;nbsp; YYYY&lt;BR /&gt;Policy Date:&amp;nbsp;&amp;nbsp;&amp;nbsp; 23 may&lt;BR /&gt;Blade:&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTPS Inspection&lt;BR /&gt;Origin:&amp;nbsp;&amp;nbsp;&amp;nbsp; XXXX&lt;BR /&gt;Service:&amp;nbsp;&amp;nbsp;&amp;nbsp; https (TCP/443)&lt;BR /&gt;Product Family:&amp;nbsp;&amp;nbsp;&amp;nbsp; Network&lt;BR /&gt;HTTPS Inspection Action:&amp;nbsp;&amp;nbsp;&amp;nbsp; Error&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 23:03:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182213#M33396</guid>
      <dc:creator>IsaacO</dc:creator>
      <dc:date>2023-05-25T23:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182226#M33403</link>
      <description>&lt;P&gt;The error states that the GW cannot validate the server certificate. If it only happens to some of the connections to the same server and not all, look if you have any intermittent connectivity failures on that GW. Also, it might be that the destination IP hosts multiple web servers, some of them with bad certificates.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 05:58:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182226#M33403</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-05-26T05:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182283#M33421</link>
      <description>&lt;P&gt;Thanks for answering _Val_.&lt;/P&gt;&lt;P&gt;Do you think that updating the certificate database can help?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;A title="https://support.checkpoint.com/results/sk/sk64521" href="https://support.checkpoint.com/results/sk/sk64521" target="_blank" rel="noreferrer noopener"&gt;sk64521&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 16:01:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182283#M33421</guid>
      <dc:creator>IsaacO</dc:creator>
      <dc:date>2023-05-26T16:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182292#M33422</link>
      <description>&lt;P&gt;100% that can only help, not make it worse. So, make sure below is enabled as per my screenshots and if you need zip file, happy to send it over. Just a small disclaimer, though couple of people on here used it and was fine, dont "shoot" the messenger if something goes sideways lol&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21099iA53823A3D481D04A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21100i9232CBD42A192F86/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 17:08:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182292#M33422</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-26T17:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182296#M33423</link>
      <description>&lt;P&gt;In case you need latest updated zip file, I attached it. Again, its totally your decision if you wish to use it, but I can guarantee its totally clean and working.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21101i45996E4B8327DC97/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 17:41:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182296#M33423</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-26T17:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182297#M33424</link>
      <description>&lt;P&gt;Thanks a lot for the help Andy.&lt;BR /&gt;I really appreciate it.&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Carlos Isaac!&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 17:47:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182297#M33424</guid>
      <dc:creator>IsaacO</dc:creator>
      <dc:date>2023-05-26T17:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182299#M33425</link>
      <description>&lt;P&gt;Any time, happy to help. Let us know if any issues, I have working R81.20 lab with windows 10 and https inspection on, so can test anything needed.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CheckpointClappingGIF.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21102i21430771F256CA23/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CheckpointClappingGIF.gif" alt="CheckpointClappingGIF.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; Andy&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 17:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182299#M33425</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-26T17:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182300#M33426</link>
      <description>&lt;P&gt;It might, but we need to figure out first, what we are dealing with. If it is an intermittent issue for the same server, connectivity is the prime suspect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 19:02:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182300#M33426</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-05-26T19:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182321#M33433</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;makes a good point Isaac. It really depends if its intermittent issue or not. I mean, you can certainly update certificate list, its not going to make it worse, but there is no guarantee it would make it better either.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 20:05:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182321#M33433</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-26T20:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182454#M33444</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for your support.&lt;/P&gt;&lt;P&gt;The problem that we had specifically was with some servers with Workload Security agents that were not synchronizing with the cloud. One of our team had created a rule in the FW but at the destination it had only one IP that was the one that gave us the HTTPS Inspection error.&lt;BR /&gt;Reading the Trend Micro documentation, you have to add some domains (130) the Security, APCL and HTTPS INSPECTION rules were created with said group of Trend Micro domains and Problem solved.&lt;/P&gt;&lt;P&gt;&lt;A href="https://cloudone.trendmicro.com/docs/workload-security/communication-ports-urls-ip/#Deep3" target="_blank"&gt;https://cloudone.trendmicro.com/docs/workload-security/communication-ports-urls-ip/#Deep3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;By the way, although the problem is solved I have to update the certificate database so I will follow your recommendation&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards!!&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 23:33:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182454#M33444</guid>
      <dc:creator>IsaacO</dc:creator>
      <dc:date>2023-05-29T23:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182455#M33445</link>
      <description>&lt;P&gt;Sounds good...keep us posted.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 23:42:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182455#M33445</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-29T23:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182456#M33446</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;I wanted to tell you something else, just my own experience, as well as one customer I worked with for https inspection. So, when I tested this in the lab (R80.40, R81.10 and R81.20), I would simply install https inspection cert generated (follow on screen prompt) and it would work without any issues. Customer first tested it on one machine and had problem, so he reinstalled the cert and placed it in trusted root and worked fine. Then they tried few machines and some worked okay, some did not, following exact same process.&lt;/P&gt;
&lt;P&gt;They had Trend Micro before going with CP, told me they never had this sort of problem, but turns out after they upgraded their environment to R81.10, all just worked fine. So, I would say if you have cert in trusted root, thats 100% correct.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 00:04:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182456#M33446</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-30T00:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182458#M33447</link>
      <description>&lt;P&gt;It is an interesting fact, to comment that the environment we have is R80.40 and we plan to update it to R81.10.&lt;BR /&gt;So I hope that by updating the Certificates and upgrading to R81.10 there will be no more problems in the future.&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Isaac.&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 00:43:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182458#M33447</guid>
      <dc:creator>IsaacO</dc:creator>
      <dc:date>2023-05-30T00:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Action:Error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182459#M33448</link>
      <description>&lt;P&gt;Im sure it would be better.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 00:45:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Action-Error/m-p/182459#M33448</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-30T00:45:47Z</dc:date>
    </item>
  </channel>
</rss>

