<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS inspection block page issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246077#M47959</link>
    <description>&lt;P&gt;Thank you &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8345"&gt;@Tom_Hinoue&lt;/a&gt; ! Good to know we're not alone. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Going to DM in a second.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Apr 2025 17:00:07 GMT</pubDate>
    <dc:creator>Teddy_Brewski</dc:creator>
    <dc:date>2025-04-09T17:00:07Z</dc:date>
    <item>
      <title>HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/128026#M18610</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope someone can shed some light on this and provide some suggestions : ). So, here is the situation.&lt;/P&gt;
&lt;P&gt;Customer has R81 mgmt and R80.40 jumbo 120 HA cluster. All works fine, but for some odd reason, with https inspection enabled, pages are blocked as per desired categories, BUT, user check block page seems to work super random. So say you go to gambling site, it gets blocked on chrome, but not on safari on mac...then on windows, its also very random, really depends site you go to if blocked page notification comes up or not.&lt;/P&gt;
&lt;P&gt;We verified all the rules, logs show correct action and categories, so Im really not sure how to troubleshoot this. We do have TAC case, but wanted to do proper testing myself first.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if this info is worth much, but say if you try facebook.com, it simply shows connection was reset, yet log shows facebook is blocked according to right rule.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If someone could give any suggestions/guidance on this, would be greatly appreciated!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks as always.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 00:21:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/128026#M18610</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-26T00:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/128028#M18611</link>
      <description>&lt;P&gt;All of that sounds like some pages are NOT getting HTTPS Inspection applied as&amp;nbsp;that is required for the block page to show up.&lt;BR /&gt;If HTTPS Inspection isn't enabled, or isn't happening for some reason, the only option to block a connection is a TCP RST.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 01:20:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/128028#M18611</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-26T01:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/128029#M18612</link>
      <description>&lt;P&gt;I agree with you 100%, but the question is why...any good approach to this behavior?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks as always.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 01:30:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/128029#M18612</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-26T01:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/128032#M18614</link>
      <description>&lt;P&gt;If it were me, I'd probably be looking at debugging wstlsd.&lt;BR /&gt;TAC may have some other suggestions as well.&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105559&amp;amp;partition=Advanced&amp;amp;product=HTTPS" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105559&amp;amp;partition=Advanced&amp;amp;product=HTTPS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 01:39:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/128032#M18614</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-26T01:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/128033#M18615</link>
      <description>&lt;P&gt;That sounds good...I may call into TAC tomorrow to see if they have any other suggestions. Tx!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 01:41:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/128033#M18615</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-26T01:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246059#M47955</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you recall any tips from TAC?&lt;/P&gt;&lt;P&gt;We're experiencing the same(?) issue with 1555 SMB appliances running R81.10.17 (996004508) with &lt;SPAN class=""&gt;Application Control&lt;/SPAN&gt; and &lt;SPAN class=""&gt;URL Filtering blades&lt;/SPAN&gt; enabled.&amp;nbsp; HTTPS Inspection is not enabled, but we do have "Categorize HTTPS websites" checked.&lt;/P&gt;&lt;P&gt;Accessing http websites that fall into a blocked category results in a blocked page -- no issues here.&lt;/P&gt;&lt;P&gt;Accessing the same website over https doesn't produce the blocked page, but rather Connection Reset error in the browser. Also, there is some random behavior observed when nothing is blocked with certain browsers.&lt;/P&gt;&lt;P&gt;Logs do show correct action and category.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 13:18:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246059#M47955</guid>
      <dc:creator>Teddy_Brewski</dc:creator>
      <dc:date>2025-04-09T13:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246061#M47956</link>
      <description>&lt;P&gt;This was a while ago, but I remember it worked fine after R81 upgrade, no issues. I would say you definitely need ssl inspection on for this to work right.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 13:25:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246061#M47956</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-09T13:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246066#M47958</link>
      <description>&lt;P&gt;For locally managed SMBs, we have confirmed this issue occurs in R81.10.15/R81.10.17 and a SR is opened to TAC.&lt;BR /&gt;A hotfix should be available now for this issue, so if interested open a case to TAC and they should be able to assist &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;If you need the SR number, you can DM me and I will be happy to help.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 14:10:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246066#M47958</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2025-04-09T14:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246077#M47959</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8345"&gt;@Tom_Hinoue&lt;/a&gt; ! Good to know we're not alone. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Going to DM in a second.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 17:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246077#M47959</guid>
      <dc:creator>Teddy_Brewski</dc:creator>
      <dc:date>2025-04-09T17:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246079#M47960</link>
      <description>&lt;P&gt;gotcha. Will reply in DM regarding what I know.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 17:35:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246079#M47960</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2025-04-09T17:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246084#M47961</link>
      <description>&lt;P&gt;To show a block page, we need to issue an HTTP Redirect to the UserCheck portal.&lt;BR /&gt;For HTTPS connections, this is impossible to do unless&amp;nbsp;HTTPS Inspection is enabled.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 19:44:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246084#M47961</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-09T19:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246091#M47962</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/26978"&gt;@Teddy_Brewski&lt;/a&gt;&amp;nbsp;What&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;said is 100% correct. Think of the fw as MITM (man in the middle) in this case...if ssl inspection is off, there is literally nothing to "intercept".&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 21:24:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246091#M47962</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-09T21:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection block page issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246092#M47963</link>
      <description>&lt;P&gt;On another note, but in the same context, check out what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;said on November 23rd, 2021 in below post, its perfect explanation.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Categorize-HTTPS-Websites/m-p/134729/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufEtXQzJBQUFSS0w3WDNXfDEzNDcyOXxTVUJTQ1JJUFRJT05TfGhL#M20231" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Categorize-HTTPS-Websites/m-p/134729/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufEtXQzJBQUFSS0w3WDNXfDEzNDcyOXxTVUJTQ1JJUFRJT05TfGhL#M20231&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 21:28:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-block-page-issue/m-p/246092#M47963</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-09T21:28:19Z</dc:date>
    </item>
  </channel>
</rss>

