<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS inspection: Inspection despite exclusion? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/207721#M39332</link>
    <description>&lt;P&gt;Sounds like you did it properly. Personally though, I ALWAYS use wildcard for https bypass, ie *printing.post.de*, Im sure that would work. If you give it a go, you can test, something like below screnshot&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24723iC094A1BA2D1B56BD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2024 12:49:11 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-03-04T12:49:11Z</dc:date>
    <item>
      <title>HTTPS inspection: Inspection despite exclusion?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/207701#M39328</link>
      <description>&lt;P&gt;hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i've created an exclusion for a website like printing.post.de. To do this i went to HTTPS Inspection Blade, created a policy. As Source i chose an Access Role. Theres an Active Directory Group behind it.&lt;/P&gt;&lt;P&gt;As Destination i created an Object "domain" like .printing.post.de. Action is "Bypass". Saved and installed.&lt;/P&gt;&lt;P&gt;It works like this for almost all users but one. Theres one user, thats also part of the AD Group, that triggers the HTTPS inspection.&lt;/P&gt;&lt;P&gt;The website isnt working for that user and i can see that the site is inspected in the logfiles&lt;/P&gt;&lt;P&gt;There are no known differences between that user and all the others&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any hints?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 09:22:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/207701#M39328</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2024-03-04T09:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection: Inspection despite exclusion?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/207721#M39332</link>
      <description>&lt;P&gt;Sounds like you did it properly. Personally though, I ALWAYS use wildcard for https bypass, ie *printing.post.de*, Im sure that would work. If you give it a go, you can test, something like below screnshot&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24723iC094A1BA2D1B56BD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 12:49:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/207721#M39332</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-04T12:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection: Inspection despite exclusion?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/207741#M39334</link>
      <description>&lt;P&gt;Note that this can match more sites than you might expect. Among other things, it would match printing.post.de.virusbiz.ru.&lt;/P&gt;
&lt;P&gt;I posted &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Custom-Application-Site-Findings/m-p/179606" target="_self"&gt;an analysis of what a custom application/site object matches&lt;/A&gt; a little under a year ago.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 14:40:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/207741#M39334</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-03-04T14:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection: Inspection despite exclusion?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/207744#M39335</link>
      <description>&lt;P&gt;Thats very true, agree. Thats a danger in using those I suppose, though personally, I never had an issue.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 14:42:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/207744#M39335</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-04T14:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection: Inspection despite exclusion?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/223824#M42957</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;today i tried to cleanup our smartconsole a bit. We use at the moment single domains for those httpsi rules, and not an application group&lt;/P&gt;&lt;P&gt;i created now an Application&amp;nbsp; (httpsi Whitelist)and added some websites there&lt;/P&gt;&lt;P&gt;i then created a new rule with "source" as computergroup, Destination internet and category&amp;nbsp;"httpsi Whitelist". Action bypass. very similar to your screenshot&lt;/P&gt;&lt;P&gt;But it wont work. Websites are inspected, though. Is there anything else needed for this?&lt;/P&gt;&lt;P&gt;it looks like attached. IT consists of our IT Department computers. the whitelist contains only one website with no special setups&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 06:55:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/223824#M42957</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2024-08-16T06:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection: Inspection despite exclusion?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/223844#M42965</link>
      <description>&lt;P&gt;Here is the key. You need to ensure those sites are ALLOWED in urlf layer, as per my post below. Im positive if you do that, it will work. I had R80.30, R80.40 lab, now I have R81.20 and R82 ssl inspection lab, never an issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-lab-guide/m-p/214429#M40929" target="_blank"&gt;Https inspection lab guide - Check Point CheckMates&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-tip/m-p/219139" target="_blank"&gt;Https inspection tip - Check Point CheckMates&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 12:32:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-Inspection-despite-exclusion/m-p/223844#M42965</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-16T12:32:49Z</dc:date>
    </item>
  </channel>
</rss>

