<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log outbound HTTP requests  with HTTPS inspection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-outbound-HTTP-requests-with-HTTPS-inspection/m-p/187806#M34629</link>
    <description>&lt;P&gt;1. R80.30 is out of support for a while now.&lt;/P&gt;
&lt;P&gt;2. Try the "Extended log" option for your needs.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2023 08:12:50 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-07-27T08:12:50Z</dc:date>
    <item>
      <title>Log outbound HTTP requests  with HTTPS inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-outbound-HTTP-requests-with-HTTPS-inspection/m-p/187805#M34628</link>
      <description>&lt;P&gt;Hello experts.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We are investigating unusual outbound traffic on one of our customers with CP Gateways R80.30 Build 215 (Take 227).&lt;BR /&gt;We established HTTPS inspection of outbound traffic. Configured Access rules and HTTPSi policy for inspection of specific set of hosts source and destinations.&lt;/P&gt;&lt;P&gt;In logs we can observe usual staff for L4 like src IP, src User (from Identity Awareness), dst IP, dst FQDN (resource from HTTPi), etc.&lt;/P&gt;&lt;P&gt;Now we need to understand what kind of queries and HTTP requests (GET/POST) were sent in those sessions.&lt;/P&gt;&lt;P&gt;Dear community members,&lt;BR /&gt;could you please tell me how to log/monitor L7 queries with Check Point (like on WAF/LB for Web Inspection)?&lt;BR /&gt;Before asking I’ve searched for this topic on the Check Mates and didn’t find anything suitable. Is it possible after all to do it with CP Gateway?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 08:09:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-outbound-HTTP-requests-with-HTTPS-inspection/m-p/187805#M34628</guid>
      <dc:creator>T-pix</dc:creator>
      <dc:date>2023-07-27T08:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Log outbound HTTP requests  with HTTPS inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-outbound-HTTP-requests-with-HTTPS-inspection/m-p/187806#M34629</link>
      <description>&lt;P&gt;1. R80.30 is out of support for a while now.&lt;/P&gt;
&lt;P&gt;2. Try the "Extended log" option for your needs.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 08:12:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-outbound-HTTP-requests-with-HTTPS-inspection/m-p/187806#M34629</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-07-27T08:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Log outbound HTTP requests  with HTTPS inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-outbound-HTTP-requests-with-HTTPS-inspection/m-p/187822#M34634</link>
      <description>&lt;P&gt;Oh yes. Extended logging for specific Access rule does the thing. Thank you very much.&lt;/P&gt;&lt;P&gt;And yes, we are planning to upgrade to R81.10.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 10:59:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-outbound-HTTP-requests-with-HTTPS-inspection/m-p/187822#M34634</guid>
      <dc:creator>T-pix</dc:creator>
      <dc:date>2023-07-27T10:59:14Z</dc:date>
    </item>
  </channel>
</rss>

