<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection policy in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184076#M33775</link>
    <description>&lt;P&gt;First screenshot: Original Dest GW, Transl. Dest BWAPP server&amp;nbsp; ??? I see no original source...&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jun 2023 12:25:09 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-06-15T12:25:09Z</dc:date>
    <item>
      <title>HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184068#M33771</link>
      <description>&lt;P&gt;I want HTTPS inspection policy to be implemented on this NAT rule that is configured to NAT a traffic towards a BWAPP server. I also want a specific certificate to be used for the inspection but I am unable to do so. Inspite of configuring a HTTPS inspection policy for the NAT policy it is not being implemented.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Concern_1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21433i07047CA7CDDC0F8B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Concern_1.png" alt="Concern_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Concern_2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21434i430D4B71222DD505/image-size/large?v=v2&amp;amp;px=999" role="button" title="Concern_2.png" alt="Concern_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 10:57:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184068#M33771</guid>
      <dc:creator>EvilGenius</dc:creator>
      <dc:date>2023-06-15T10:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184076#M33775</link>
      <description>&lt;P&gt;First screenshot: Original Dest GW, Transl. Dest BWAPP server&amp;nbsp; ??? I see no original source...&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 12:25:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184076#M33775</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-06-15T12:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184081#M33778</link>
      <description>&lt;P&gt;Original Source is Any, Just couldn't get it into the Screenshot,&amp;nbsp;&lt;SPAN&gt;CCSE CCTE CCSM SMB Specialist admirer&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 12:51:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184081#M33778</guid>
      <dc:creator>EvilGenius</dc:creator>
      <dc:date>2023-06-15T12:51:20Z</dc:date>
    </item>
    <item>
      <title>HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184083#M33782</link>
      <description>&lt;P&gt;I configured a HTTPS Inspection policy which uses a self assigned certificate but through the log the traffic is only being inspected and not allowed. Every packet is being dropped, similarly as it can be noticed in the screenshot provided below I believe the Action should be allowed/blocked but only HTTPS inspect is displayed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Concern_3.png" style="width: 947px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21437i2151D448D96A5617/image-size/large?v=v2&amp;amp;px=999" role="button" title="Concern_3.png" alt="Concern_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 12:54:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184083#M33782</guid>
      <dc:creator>EvilGenius</dc:creator>
      <dc:date>2023-06-15T12:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184084#M33780</link>
      <description>&lt;P&gt;So why is the GW Source in screenshot 2 ? Translated Source is Original == Any, so how should that https rule match here ?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 12:56:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184084#M33780</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-06-15T12:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184085#M33781</link>
      <description>&lt;P&gt;Use the column picker to add the "Certificates" column.&amp;nbsp; You can then select the correct certificate for inbound inspection.&lt;/P&gt;
&lt;P&gt;This assumes you imported the proper server certificate first though.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 12:58:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184085#M33781</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-06-15T12:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184088#M33784</link>
      <description>&lt;P&gt;I merged the other thread you created on this configuration since it stems from the same misconfiguration, most likely.&lt;/P&gt;
&lt;P&gt;The decision to perform HTTPS Inspection needs to happens before Access Rules or NAT are applied.&lt;BR /&gt;Which means your HTTPS Inspection rules should be created accordingly.&lt;BR /&gt;I assume based on your configuration that you're trying to forward connections that occur to the firewall's external IP to the host ACFW-CHKP-BWAPP.&lt;BR /&gt;The "certificate' column in the rule would be where you'd configure the private key to use when connecting to ACFW-CHKP-BWAPP.&lt;BR /&gt;This means your HTTPS Inspection rule should have "any" as the source (not the gateway as shown).&lt;/P&gt;
&lt;P&gt;I suspect this will also fix the issue with the NAT rule.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 13:11:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184088#M33784</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-15T13:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184165#M33819</link>
      <description>&lt;P&gt;Thank you for the wonderful support everyone. Now I am successfully able to implement https inspection on the desired traffic interface but the traffic is only being inspected and all the normal traffic from that rule are getting blocked after inspection. Is there something else that I have to look into? It's only been a while since I have been using Checkpoint firewall so I am baffled with some features. The requirement was to inspect HTTPS traffic from performance subnet to lan subnet.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="concern_4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21452iE32E4C8B9D524D86/image-size/large?v=v2&amp;amp;px=999" role="button" title="concern_4.png" alt="concern_4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="concern_5.png" style="width: 172px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21453i3F9D4CA999391228/image-size/large?v=v2&amp;amp;px=999" role="button" title="concern_5.png" alt="concern_5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have also included a certificate that is going to be used for the inspection but while passing traffic through the policy all the traffics are only being inspected and dropped which can be noticed in the log.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 04:44:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184165#M33819</guid>
      <dc:creator>EvilGenius</dc:creator>
      <dc:date>2023-06-16T04:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184204#M33835</link>
      <description>&lt;P&gt;HTTPS Inspection policy only decrypts the appropriate traffic.&lt;BR /&gt;You must still have an Access Policy rule that permits the relevant traffic.&lt;BR /&gt;What precise rule is being matched per the traffic logs?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 19:07:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184204#M33835</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-16T19:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184211#M33836</link>
      <description>&lt;P&gt;The Access Policy rule that is being matched with the HTTPS inspection policy is presented below:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="concern_5.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21457i865CF76AAADB9A3B/image-size/large?v=v2&amp;amp;px=999" role="button" title="concern_5.png" alt="concern_5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and the HTTPS inspection configured for this Access policy is:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Concern_6.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21458i5D4F2209DC8E835A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Concern_6.png" alt="Concern_6.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Similarly the log generated:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Concern_3.png" style="width: 947px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21459i8398B65BE5EA1C7F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Concern_3.png" alt="Concern_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 19:26:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184211#M33836</guid>
      <dc:creator>EvilGenius</dc:creator>
      <dc:date>2023-06-16T19:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184214#M33837</link>
      <description>&lt;P&gt;Just to confirm, the source LAN is internal, correct?&lt;BR /&gt;I suspect you're going to need a TAC case to get to the bottom of this: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 20:31:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184214#M33837</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-16T20:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184224#M33840</link>
      <description>&lt;P&gt;Yes, the source is internal but is from different interfaces and subnets.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2023 08:22:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-policy/m-p/184224#M33840</guid>
      <dc:creator>EvilGenius</dc:creator>
      <dc:date>2023-06-17T08:22:25Z</dc:date>
    </item>
  </channel>
</rss>

