<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Http parsing error in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210822#M39937</link>
    <description>&lt;P&gt;Ah first fw is not Check Point that changes is. It still can be config error. Start with the SK's below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108202" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108202&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk65123" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk65123&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk64521" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk64521&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk112214" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112214&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2024 11:57:20 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-04-09T11:57:20Z</dc:date>
    <item>
      <title>Http parsing error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210695#M39924</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;In our network environment, we have two firewalls. We attempted to enable SSL inspection on both firewalls, but encountered an error message: “HTTP parsing error.” Notably, both firewalls utilize the same self-signed certificate for outbound inspection. Surprisingly, when we enable HTTPS inspection on only one of the firewalls, everything functions correctly.&lt;/P&gt;&lt;P&gt;Checkpoint firewall is second device in architecture.&lt;/P&gt;&lt;P&gt;the issue is happened on different sites, for example ssllabs.com, apple.com.&lt;/P&gt;&lt;P&gt;some sites work correctly for example udemy.com with inspection enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What steps should we take to troubleshoot this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 13:19:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210695#M39924</guid>
      <dc:creator>Max91</dc:creator>
      <dc:date>2024-04-08T13:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Http parsing error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210780#M39930</link>
      <description>&lt;P&gt;On the problematic firewall could you check if you can access the internet from this gateway?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108202" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108202&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check:&amp;nbsp;&lt;/P&gt;
&lt;H4 id="Best Practices - Internet connection"&gt;(Part 2 - 3) Best Practices: Internet connection&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I am not sure if 2 Check Point firewalls in the same traffic flow is good with both HTTPS inspection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Documentation states:&amp;nbsp;&lt;SPAN&gt;HTTPS Inspection can be enabled on a single Security Gateway at first, and then expanded to additional Security Gateways.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Does not mention if they can be inline, so worth checking. Maybe someone else knows that here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 08:10:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210780#M39930</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-04-09T08:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Http parsing error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210800#M39933</link>
      <description>&lt;P&gt;Can you give a sketch of the network topology ?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 10:49:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210800#M39933</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-04-09T10:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Http parsing error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210817#M39935</link>
      <description>&lt;P&gt;Hey,&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this scenario, client access to the internet through two firewalls. The first one is a LAN firewall (not Checkpoint) that performs LAN segmentation and forwards traffic to the second firewall, which is a WAN firewall that perfom a accses to internet&amp;nbsp; (Checkpoint).&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 11:38:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210817#M39935</guid>
      <dc:creator>Max91</dc:creator>
      <dc:date>2024-04-09T11:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Http parsing error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210819#M39936</link>
      <description>&lt;P&gt;Hey,&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first fw is not Checkpoint&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I activate ssl decryption on one of them everything works fine, the problems start when on both of them try to opens tls traffic.&lt;/P&gt;&lt;P&gt;All Firewalls have access to the internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 11:43:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210819#M39936</guid>
      <dc:creator>Max91</dc:creator>
      <dc:date>2024-04-09T11:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Http parsing error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210822#M39937</link>
      <description>&lt;P&gt;Ah first fw is not Check Point that changes is. It still can be config error. Start with the SK's below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108202" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108202&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk65123" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk65123&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk64521" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk64521&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk112214" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112214&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 11:57:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210822#M39937</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-04-09T11:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Http parsing error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210830#M39942</link>
      <description>&lt;P&gt;Sorry, no offense meant - but i just read your issue to my tech support collegues and we had a big laugh together &lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;It is no wonder that this does not work; and what could be achieved by 2 times SSL inspection ? I would suggest to enable SSL inspection on CP GW only.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 12:28:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210830#M39942</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-04-09T12:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: Http parsing error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210855#M39947</link>
      <description>&lt;P&gt;Firewall vendors may employ a variety of for detecting threats within encrypted traffic, such as signature-based detection, behavior analysis, machine learning algorithms, heuristics, anomaly detection, or sandboxing. Each technique has its strengths and weaknesses, and vendors may prioritize different approaches based on their research, development, and expertise&lt;/P&gt;&lt;P&gt;This is in addition to the constraints that exist in the organization due to a complex topology&lt;/P&gt;&lt;P&gt;In addition, I don't see any problem with ssl decryption by different vendorim, in other environment there are both firewalls, and proxy's, and products for ssl visabilty, which decrypt tls one after the other without any problem.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 13:29:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210855#M39947</guid>
      <dc:creator>Max91</dc:creator>
      <dc:date>2024-04-09T13:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Http parsing error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210862#M39953</link>
      <description>&lt;P&gt;Double https inspection makes certificate management complex. It is done via MITM and client needs to trust the certificate from gateway. In this case 2. In this case the first firewall will be the client from Check Point point of view. Due that the first gateway sets up the connection on it's own (if inspected).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;client &amp;lt;-&amp;gt; first firewall (MITM HTTPS inspection) &amp;lt;-&amp;gt; Check Point (MITM HTTPS inspection) &amp;lt;-&amp;gt; Web server&lt;/P&gt;
&lt;P&gt;The Check Point will be inspecting traffic initiated from the first firewall. The first firewall starts the traffic because it is doing MITM for the client. I am getting headache only thinking about this scenario.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 13:53:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Http-parsing-error/m-p/210862#M39953</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-04-09T13:53:45Z</dc:date>
    </item>
  </channel>
</rss>

