<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection for Mobile Devices in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230976#M44480</link>
    <description>&lt;P&gt;Thank you for your insight&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/117290"&gt;@oa_munich&lt;/a&gt;!&lt;/P&gt;&lt;P&gt;So, it is almost impossible to block mobile application via firewall, right?&lt;/P&gt;&lt;P&gt;I was thinking about cert pinning before, however, i am looking for any idea from CP firewall how to block such social media application and access social media via browser in mobile devices.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Oct 2024 12:46:58 GMT</pubDate>
    <dc:creator>spinazdoo</dc:creator>
    <dc:date>2024-10-28T12:46:58Z</dc:date>
    <item>
      <title>HTTPS Inspection for Mobile Devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230956#M44474</link>
      <description>&lt;P&gt;Hi Checkmates!&lt;/P&gt;&lt;P&gt;We would like to enable HTTPS Inspection to have better security with URLF and App Control policy to tackle users query to inappropriate website and social media sites.&lt;/P&gt;&lt;P&gt;Due to mandatory install certificate on every devices, how about for mobile devices like android, ipad, etc? Is it mandatory to install in every mobile devices to block them access social media sites?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The objectives is have equal policy and protection for laptop and mobile devices. If facebook or X blocked via URL Filtering, we must blocking it as well in mobile devices application. Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 09:54:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230956#M44474</guid>
      <dc:creator>spinazdoo</dc:creator>
      <dc:date>2024-10-28T09:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Mobile Devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230962#M44476</link>
      <description>&lt;P&gt;Most mobile applications use certificate pinning, and they won't trust your certificate in the first place (facebook, reddit, &lt;STRONG&gt;...).&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If&lt;/STRONG&gt; you'd like the devices to trust decrypted and resigned traffic, you'd have to install certificates on your mobile devices too. MDM solutions, such as InTune, AirWatch, etc can help with that. If you "only" would like to deny certain traffic/URLS, the mobile devices won't get to see the certificate you will be resigning with - so no need to install it, though you need to make sure you bypass allowed traffic, which in turn won't get inspected / resigned.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 10:25:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230962#M44476</guid>
      <dc:creator>oa_munich</dc:creator>
      <dc:date>2024-10-28T10:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Mobile Devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230976#M44480</link>
      <description>&lt;P&gt;Thank you for your insight&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/117290"&gt;@oa_munich&lt;/a&gt;!&lt;/P&gt;&lt;P&gt;So, it is almost impossible to block mobile application via firewall, right?&lt;/P&gt;&lt;P&gt;I was thinking about cert pinning before, however, i am looking for any idea from CP firewall how to block such social media application and access social media via browser in mobile devices.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 12:46:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230976#M44480</guid>
      <dc:creator>spinazdoo</dc:creator>
      <dc:date>2024-10-28T12:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Mobile Devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230985#M44483</link>
      <description>&lt;P&gt;No, you absolutely can! The mobile device will attempt to open a connection to the target, the firewall would inspect it&amp;nbsp; and block it. The mobile device won't get to see the inspected packets (which are decrypted and re-encrypted using your certificate), therefore it won't need your certificate.&lt;/P&gt;&lt;P&gt;For the permitted traffic - if you intend to not only bypass what you inspect&amp;nbsp; - you'd need to distribute your certificate, so mobile devices would trust the traffic you permit.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 13:24:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230985#M44483</guid>
      <dc:creator>oa_munich</dc:creator>
      <dc:date>2024-10-28T13:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Mobile Devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230998#M44487</link>
      <description>&lt;P&gt;While you will get better (more accurate) results with HTTPS Inspection, you can certainly block certain kinds of traffic without it as the App Control/URLF policy reads the SNI of the relevant traffic.&lt;BR /&gt;Make sure you block QUIC in the policy.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 13:43:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/230998#M44487</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-28T13:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Mobile Devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/231035#M44500</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Make sure you block QUIC in the policy.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Btw, according to the release notes:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Added support of HTTP/3 protocol over QUIC transport (UDP) for Network Security, Threat Prevention, and Sandboxing&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Not sure what this means exactly, but QUIC seems to be partially inspected in R82 now.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 20:06:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/231035#M44500</guid>
      <dc:creator>oa_munich</dc:creator>
      <dc:date>2024-10-28T20:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Mobile Devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/231057#M44507</link>
      <description>&lt;P&gt;We have support for QUIC in R82, yes.&lt;BR /&gt;However, I presumed the original poster&amp;nbsp;isn't yet running R82.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 21:54:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/231057#M44507</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-28T21:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Mobile Devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/231062#M44509</link>
      <description>&lt;P&gt;nice&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 22:54:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/231062#M44509</guid>
      <dc:creator>otto_w</dc:creator>
      <dc:date>2024-10-28T22:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Mobile Devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/231066#M44512</link>
      <description>&lt;P&gt;Personally, I dont know if that can work with the fw itself, never tested it, but we have a client that uses harmony mobile for mobile phones in particular and works really well with https inspection, as they used MS intune to distribute the cert that way to the users' phones.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 00:58:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/231066#M44512</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-29T00:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection for Mobile Devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/231108#M44524</link>
      <description>&lt;P&gt;Yes, I tested it in the lab, works well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 10:26:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-for-Mobile-Devices/m-p/231108#M44524</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-29T10:26:50Z</dc:date>
    </item>
  </channel>
</rss>

