<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection issues in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192795#M35658</link>
    <description>&lt;P&gt;Sounds like to you tried to use a Service and/or Destination of "Any" in your HTTPS Inspection policy which you should never do, they should be "HTTPS Default Services" and object "Internet" (not All_Internet), respectively.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Sep 2023 20:29:54 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2023-09-15T20:29:54Z</dc:date>
    <item>
      <title>HTTPS Inspection issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192742#M35639</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A customer i am assisting, have started testing https inspection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As usual, they have only added a few servers for testing purposes in their https inspection policy, but here is where the issue occurs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When they activate it, we see that traffic that isnt included in the rules are still subject to inspection, and so we have had to create a lot of exception rules, that shouldnt have been there.&lt;/P&gt;&lt;P&gt;Why would this happen?&lt;/P&gt;&lt;P&gt;I&amp;nbsp; have done this several times before, but never seen this issue before.&lt;/P&gt;&lt;P&gt;The inspection is for outbound traffic, and the traffic we have seen beeing stopped is traffic going over vpn to their central datacenter.&lt;/P&gt;&lt;P&gt;The exception fixed this as a workaround, but i am curious as to why we would need to do this in the first place, as the rules doesnt include the traffic being stopped?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;environment is R81.10.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 10:36:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192742#M35639</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2023-09-15T10:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192777#M35647</link>
      <description>&lt;P&gt;Without seeing the exact rules in question…difficult to say.&lt;BR /&gt;I suspect your initial rules were overly broad.&lt;BR /&gt;Screenshots of the rules in question would be helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 15:16:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192777#M35647</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-15T15:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192795#M35658</link>
      <description>&lt;P&gt;Sounds like to you tried to use a Service and/or Destination of "Any" in your HTTPS Inspection policy which you should never do, they should be "HTTPS Default Services" and object "Internet" (not All_Internet), respectively.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 20:29:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192795#M35658</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-09-15T20:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192896#M35674</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the input. I went over the rules again, and they are quite limited.&lt;/P&gt;&lt;P&gt;The source is just a few servers, and destination is set to Internet, with the https default services chosen,&lt;/P&gt;&lt;P&gt;So there is no real logic as to why servers not added is subject to https inspection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 11:25:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192896#M35674</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2023-09-18T11:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192960#M35687</link>
      <description>&lt;P&gt;Check your firewall/cluster topology and make sure it is complete and correct to ensure that the object Internet will match traffic properly in your HTTPS Inspection Policy, mainly:&lt;/P&gt;
&lt;P&gt;1) The External interface is properly defined&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Note that selecting the "Interface leads to DMZ" checkbox on an interface will cause traffic heading for that interface to match object Internet as well, even though that interface's topology is defined as Internal&lt;/P&gt;
&lt;P&gt;3) Make sure all interfaces are present in the defined topology, including all VLAN tag subinterfaces in use.&amp;nbsp; Traffic heading to interfaces missing from the topology definition will match object Internet as well.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 16:30:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192960#M35687</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-09-18T16:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192962#M35688</link>
      <description>&lt;P&gt;Happy to assist via remote if you are able to. I have lots of experience with https inspection, as I had spent probably close to 200 hours or more troubleshooting it in the last 3 years or so.&lt;/P&gt;
&lt;P&gt;You can always message me directly.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 16:47:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-issues/m-p/192962#M35688</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-18T16:47:01Z</dc:date>
    </item>
  </channel>
</rss>

