<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic https url redirection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35914#M91793</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got an request to do URL redirection on my customer's site. they are asking me to redirect &lt;A href="https://some.sites.com/someurl"&gt;https://some.sites.com/someurl&lt;/A&gt;&amp;nbsp;to &lt;A href="https://some.sites.com/redirectoindex"&gt;https://some.sites.com/redirectoindex&lt;/A&gt;. I&amp;nbsp;am sure this can be done by modifying Htaccess on the server itself.&amp;nbsp;But&amp;nbsp;we dont take any risk on production server, so we tried to manipulate it on the checkpoint gateway. At first i think it is possible to be done and i've tried&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk40348, and the fact... this SK is intended only work on http. does anyone have experience about this? if so, i hope you can share the answer with us. FYI.. we are using gaia R77.30 as Management Server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Thanks A lot..&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Oct 2018 00:22:00 GMT</pubDate>
    <dc:creator>gema_adhan</dc:creator>
    <dc:date>2018-10-17T00:22:00Z</dc:date>
    <item>
      <title>https url redirection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35914#M91793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got an request to do URL redirection on my customer's site. they are asking me to redirect &lt;A href="https://some.sites.com/someurl"&gt;https://some.sites.com/someurl&lt;/A&gt;&amp;nbsp;to &lt;A href="https://some.sites.com/redirectoindex"&gt;https://some.sites.com/redirectoindex&lt;/A&gt;. I&amp;nbsp;am sure this can be done by modifying Htaccess on the server itself.&amp;nbsp;But&amp;nbsp;we dont take any risk on production server, so we tried to manipulate it on the checkpoint gateway. At first i think it is possible to be done and i've tried&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk40348, and the fact... this SK is intended only work on http. does anyone have experience about this? if so, i hope you can share the answer with us. FYI.. we are using gaia R77.30 as Management Server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Thanks A lot..&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2018 00:22:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35914#M91793</guid>
      <dc:creator>gema_adhan</dc:creator>
      <dc:date>2018-10-17T00:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: https url redirection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35915#M91794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What kind ofntraffic is it? Traffic incoming from the internet to your organization? Or from your organization to the internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it a temporary confoguration or not because soon r77.30 will be end of supplort and you will need to upgrade to r80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Except for the web server and the checkpoint what other security solution do you have involvong this website&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is needed only for a direct http request for this uri or rewriting of links is needed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2018 06:48:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35915#M91794</guid>
      <dc:creator>Dor_Marcovitch</dc:creator>
      <dc:date>2018-10-17T06:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: https url redirection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35916#M91795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marcovitch Thanks for your responses.&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px; font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;What kind ofntraffic is it? Traffic incoming from the internet to your organization? Or from your organization to the internet?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px; font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;the traffic is incoming traffic that is coming from internet&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px; font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;Is it a temporary confoguration or not because soon r77.30 will be end of supplort and you will need to upgrade to r80&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px; font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;it would be permanent configuration, yeah we know it, R77.30 will be end of support next year, but most of our customer is using R77.30&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px; font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;Except for the web server and the checkpoint what other security solution do you have involvong this website&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px; font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;i think there is no other security device between the server and our checkpoint gateway.&amp;nbsp;The server reside on DMZ segement on our checkpoint gateway,&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px; font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;This is needed only for a direct http request for this uri or rewriting of links is needed?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px; font-size: 14px;"&gt;i think both soultion can be applied.&amp;nbsp;because we just need to hide&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://some.sites.com/someurl" rel="nofollow" style="color: #e45785; border: 0px; text-decoration: underline; padding: 0px calc(12px + 0.35ex) 0px 0px;"&gt;https://some.sites.com/someurl&lt;/A&gt;&amp;nbsp;from&amp;nbsp;interenet but still allowing it to be accessed from internal network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 03:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35916#M91795</guid>
      <dc:creator>gema_adhan</dc:creator>
      <dc:date>2018-10-18T03:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: https url redirection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35917#M91796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That SK refers to the HTTP Security Server, which definitely does &lt;EM&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;/EM&gt; support HTTPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To do this with HTTPS,&amp;nbsp;I believe you can do something like:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Enable HTTPS Inspection for the inbound traffic (means getting the HTTPS certificate used for the webserver)&lt;/LI&gt;&lt;LI&gt;Create an application that refers to &lt;A href="https://example.com/uri-to-redirect"&gt;https://example.com/uri-to-redirect&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Create a UserCheck action that redirects to &lt;A href="https://example.com/redirect-to-uri"&gt;https://example.com/redirect-to-uri&lt;/A&gt;&amp;nbsp;(this is an option with a UserCheck action)&lt;/LI&gt;&lt;LI&gt;Create a rule that refers to this application and with action Drop and the UserCheck action you created.&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 23:20:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35917#M91796</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-19T23:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: https url redirection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35918#M91797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon, sorry for late response. Thanks for your advice Dameon... I will ty it on my lab first before propose it the the user. and I will inform to you the result. But...Is there alternative way to accomplish this task instead of using https inspection because it will add the load of the gateway since there is limititation on the hardware that we used.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 09:11:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35918#M91797</guid>
      <dc:creator>gema_adhan</dc:creator>
      <dc:date>2018-10-24T09:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: https url redirection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35919#M91798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is technically impossible to do any sort of URL redirection without terminating the HTTPS connection.&lt;/P&gt;&lt;P&gt;Currently, the only way to do this is HTTPS Inspection.&lt;/P&gt;&lt;P&gt;Note: you can enable it for just inbound to the one site and be in "bypass" mode for everything else.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2018 13:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-url-redirection/m-p/35919#M91798</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-24T13:53:51Z</dc:date>
    </item>
  </channel>
</rss>

