<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Apple and HTTPS Inspection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/222744#M42709</link>
    <description>&lt;P&gt;Me, personally, I just do *apple* and call it a day lol&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 05 Aug 2024 14:11:19 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-08-05T14:11:19Z</dc:date>
    <item>
      <title>Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176039#M32167</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am about to implement HTTPS Inspection but there are some issues with Mac's and software updates.&lt;/P&gt;&lt;P&gt;Current HTTPS Inspect rules bypass 17.0.0.0/8 and itunes.apple.com but still there are some issues.&lt;/P&gt;&lt;P&gt;Are there any plans for an Updatable Apple object or anyone else that has run into this issue that has found a solution ?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 10:14:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176039#M32167</guid>
      <dc:creator>nooni</dc:creator>
      <dc:date>2023-03-24T10:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176043#M32171</link>
      <description>&lt;P&gt;Ah, I remember my struggles on this subject with a customer couple of years back who is 95% Apple shop.&lt;/P&gt;
&lt;P&gt;What we ended up doing was whitelist followimg:&lt;/P&gt;
&lt;P&gt;*apple*&lt;BR /&gt;*itunes*&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;and bunch of Apple IP ranges&lt;/P&gt;
&lt;P&gt;Sadly, I wish there were appropriate updatable objects there. Now in all fairness, all other major fw vendors dont have those updatable objects either when it comes to Apple : - (&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 10:24:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176043#M32171</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-24T10:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176044#M32172</link>
      <description>&lt;P&gt;Thanks, will try that and i hope that someone from Check Point can update us on plans for an Updatable object &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 10:34:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176044#M32172</guid>
      <dc:creator>nooni</dc:creator>
      <dc:date>2023-03-24T10:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176047#M32173</link>
      <description>&lt;P&gt;Did you try to use the HTTPS services recommended bypass Updateable object and Apple Smart Accel Updateable object for exception?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 10:53:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176047#M32173</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-24T10:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176049#M32174</link>
      <description>&lt;P&gt;Yes Https inspect bypass both updatable objects is used to bypass.&lt;/P&gt;&lt;P&gt;Could not find any Apple related category in Updatable objects list ?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 10:57:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176049#M32174</guid>
      <dc:creator>nooni</dc:creator>
      <dc:date>2023-03-24T10:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176059#M32177</link>
      <description>&lt;P&gt;I dont think you would find it, as it simply does not exist : - (. Anyway, I gotta get ready to drive to test center to give my CCTE exam, but when I come back, will fire up my https inspection lab in R81.20 and verify all this.&lt;/P&gt;
&lt;P&gt;Cheers mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 11:24:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176059#M32177</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-24T11:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176060#M32178</link>
      <description>&lt;P&gt;Thanks, it was a response to GW Albrecht &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Good luck on your exam!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 11:29:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176060#M32178</guid>
      <dc:creator>nooni</dc:creator>
      <dc:date>2023-03-24T11:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176061#M32179</link>
      <description>&lt;P&gt;Tx mate! Yea, I know it was response to our good man Guenther :). Anyway, will check when Im back, hopefully around 11 am EST.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 11:40:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176061#M32179</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-24T11:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176075#M32181</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Apple.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20235iEAAA9D607A0A6D8C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Apple.jpg" alt="Apple.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 13:01:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176075#M32181</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-24T13:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176076#M32182</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/69604"&gt;@nooni&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you be more explicit on what are the HTTPS Inspection issues you're facing - more exactly with examples/screenshots ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've looked into this as we are running an POC to implement apple cache servers, therefore we had to make sure that Apple traffic via CheckPoints were not inspected (certificate substituted).&lt;/P&gt;
&lt;P&gt;FWL policies looks like:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Apple_Untitled.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20234i2A6D4C0A459327F9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Apple_Untitled.png" alt="Apple_Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the HTTPS Inspection, we're bypassing "apple.com" CustomApp object and "c.apple.news" .&lt;/P&gt;
&lt;P&gt;Those objects contains:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="50%" height="25px" class="lia-align-center"&gt;&lt;STRONG&gt;apple.com&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="50%" height="25px" class="lia-align-center"&gt;&lt;STRONG&gt;c.apple.news&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%" height="135px"&gt;
&lt;P&gt;*.aplle.com&lt;BR /&gt;.apple.com&lt;BR /&gt;.icloud.com&lt;BR /&gt;*.icloud.com&lt;BR /&gt;appleid.cdn-apple.com&lt;BR /&gt;.cdn-apple.com&lt;BR /&gt;@*.cdn-apple.com&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="50%" height="135px"&gt;
&lt;P&gt;c.apple.news&lt;BR /&gt;.apple.news&lt;BR /&gt;*.apple.news&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;So with that, we were able to see that the Apple cache machine, was able to register the Apple Cloud cache services, and download packages.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 13:04:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176076#M32182</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2023-03-24T13:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176077#M32183</link>
      <description>&lt;P&gt;It does exist at least since R81.20 / R81.10.00. Please do not state that something simply does not exist if the only reason for the statement is your ignorance ! No harm in telling: I never heard of, i never saw that, i do not believe it exists. But not: Does not exist...&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 13:05:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176077#M32183</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-24T13:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176104#M32189</link>
      <description>&lt;P&gt;Thats right, I see exact same thing you posted, which does literally nothing lol. I was on the call once with TAC escalations guy and customer and that was pretty much only thing he could find as well. So, factually, okay, I will give it to you, it DOES exist, but its useless &lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20237i4B58DC7564D50530/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 14:59:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176104#M32189</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-24T14:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176147#M32215</link>
      <description>&lt;P&gt;For us to have an Updatable Object, the vendor has to provide the IP ranges in a machine consumable format.&lt;BR /&gt;Without that, it’s impossible for us to accurately determine what IP ranges vendors use for what.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 20:22:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176147#M32215</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-24T20:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176234#M32239</link>
      <description>&lt;P&gt;Thank you for sharing this solution &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 06:36:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176234#M32239</guid>
      <dc:creator>nooni</dc:creator>
      <dc:date>2023-03-27T06:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176274#M32261</link>
      <description>&lt;P&gt;Thanks for sharing&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16983"&gt;@Sorin_Gogean&lt;/a&gt;&amp;nbsp;, always great advice! &lt;span class="lia-unicode-emoji" title=":flexed_biceps:"&gt;💪&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 11:51:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/176274#M32261</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-27T11:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/222723#M42707</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;Can you show us what is included in your apple software updates object?&lt;/P&gt;&lt;P&gt;We have a simular issue that ipads can no longer recieve updates when inspection is on. however we would like to limit what we exactly open.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 10:44:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/222723#M42707</guid>
      <dc:creator>HendrikS</dc:creator>
      <dc:date>2024-08-05T10:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Apple and HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/222744#M42709</link>
      <description>&lt;P&gt;Me, personally, I just do *apple* and call it a day lol&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 14:11:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Apple-and-HTTPS-Inspection/m-p/222744#M42709</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-05T14:11:19Z</dc:date>
    </item>
  </channel>
</rss>

