<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS inspection policy doubt in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96674#M78485</link>
    <description>&lt;P&gt;So there is priority&lt;BR /&gt;That is, I must first set the IP before setting up the application?&lt;/P&gt;&lt;P&gt;Does this have the documentation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Sep 2020 02:27:36 GMT</pubDate>
    <dc:creator>Chou_YiHsien</dc:creator>
    <dc:date>2020-09-14T02:27:36Z</dc:date>
    <item>
      <title>HTTPS inspection policy doubt</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96542#M78482</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question.&lt;/P&gt;&lt;P&gt;I set 2 policies on R80.40 HTTPS inspection.&lt;/P&gt;&lt;P&gt;1.src:any ,dst:google service , service port:443&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.src:any , dst:xx.xx.xx.xx , service port:443&lt;/P&gt;&lt;P&gt;Why is there no effect if the IP is placed in the second policy?&lt;BR /&gt;If you put the IP in the first one, it will be applied normally?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 06:46:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96542#M78482</guid>
      <dc:creator>Chou_YiHsien</dc:creator>
      <dc:date>2020-09-11T06:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection policy doubt</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96553#M78483</link>
      <description>&lt;P&gt;How do you mean, no effect?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 09:25:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96553#M78483</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-09-11T09:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection policy doubt</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96561#M78484</link>
      <description>&lt;P&gt;I have also already made the experience that with the HTTPS Policy you should first make the rules based on IP addresses at the top and then those based on applications below.&lt;/P&gt;&lt;P&gt;I had the applicaton based bypass rule in the first place and the policy did not work.&lt;/P&gt;&lt;P&gt;For me it seems like you have to pay attention to a certain sequence.&lt;/P&gt;&lt;P&gt;But I haven't found anything where it's documented.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 10:45:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96561#M78484</guid>
      <dc:creator>Nikolai_Borhart</dc:creator>
      <dc:date>2020-09-11T10:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection policy doubt</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96674#M78485</link>
      <description>&lt;P&gt;So there is priority&lt;BR /&gt;That is, I must first set the IP before setting up the application?&lt;/P&gt;&lt;P&gt;Does this have the documentation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 02:27:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96674#M78485</guid>
      <dc:creator>Chou_YiHsien</dc:creator>
      <dc:date>2020-09-14T02:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection policy doubt</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96901#M78486</link>
      <description>&lt;P&gt;Rules are evaluated per &lt;A href="https://community.checkpoint.com/t5/General-Management-Topics/Unified-Policy-Column-based-Rule-Matching/m-p/9888#M1693" target="_self"&gt;Column-based rule matching.&lt;/A&gt;&lt;BR /&gt;This applies to HTTPS Inspection policy as well.&lt;BR /&gt;If the connection matches the first rule, that is the rule that will apply.&lt;BR /&gt;In general, you should always have more specific rules first.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 04:46:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96901#M78486</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-17T04:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection policy doubt</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96912#M78487</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;just a small correction, for Unified Policy, and not for HTTPS Inspection, if AC/URLF and/or content inspection are in play, it might be that the connection will be matched to more than a single rule, pending streaming data decision.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 07:33:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-policy-doubt/m-p/96912#M78487</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-09-17T07:33:56Z</dc:date>
    </item>
  </channel>
</rss>

