<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS Inspection Troubleshooting  Runbook por evidência (CA, QUIC, pinning, proxy e debug wstlsd) in Brazil</title>
    <link>https://community.checkpoint.com/t5/Brazil/HTTPS-Inspection-Troubleshooting-Runbook-por-evid%C3%AAncia-CA-QUIC/m-p/274939#M52</link>
    <description>&lt;H2&gt;&lt;STRONG&gt; HTTPS Inspection Troubleshooting&amp;nbsp; Runbook por evidência (CA, QUIC, pinning, proxy e debug wstlsd)&lt;/STRONG&gt;&lt;/H2&gt;
&lt;H3&gt;Tese (como fechar RCA rápido)&lt;/H3&gt;
&lt;P&gt;Quando HTTPS Inspection “quebra”, &lt;STRONG&gt;não é um problema único&lt;/STRONG&gt;. Em campo, quase sempre cai em um destes blocos:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Trust chain no endpoint&lt;/STRONG&gt; (CA do gateway/CA interna não confiável)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Aplicação incompatível&lt;/STRONG&gt; (certificate pinning, mTLS, requisitos específicos)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Transporte fora do esperado&lt;/STRONG&gt; (&lt;STRONG&gt;QUIC/HTTP3 via UDP/443&lt;/STRONG&gt;)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Interferência de rede&lt;/STRONG&gt; (proxy explícito/autenticado, PAC, SSL inspection upstream)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Capacidade/handshake sob carga&lt;/STRONG&gt; (CPU/crypto, picos, perfil agressivo)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Bypass inesperado&lt;/STRONG&gt; (regra/objeto updatable/limitação) → “parece que não inspeciona”&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Regra TAC:&lt;/STRONG&gt; só mude configuração depois de coletar evidência mínima e isolar a variável (uma mudança por vez).&lt;/P&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;0) AVISOS TAC (impacto operacional e governança)&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;Antes de qualquer alteração (principalmente bypass e debug):&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Faça &lt;STRONG&gt;backup&lt;/STRONG&gt; do estado/configuração (e documente o baseline do que será alterado).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Execute em &lt;STRONG&gt;janela controlada&lt;/STRONG&gt;, preferencialmente com &lt;STRONG&gt;console&lt;/STRONG&gt; disponível.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Documente cada mudança&lt;/STRONG&gt; (para facilitar rollback).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Se for &lt;STRONG&gt;cluster&lt;/STRONG&gt;, planeje a coleta em &lt;STRONG&gt;todos os membros&lt;/STRONG&gt;, porque a falha/handshake pode ocorrer em qualquer nó.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;1) Fast triage em 10 minutos (sem debug)&lt;/H1&gt;
&lt;H2&gt;1.1 Confirme enforcement no cliente (prova mais rápida)&lt;/H2&gt;
&lt;P&gt;No browser, abra um site HTTPS e verifique o certificado apresentado:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Issuer = CA do gateway / CA interna&lt;/STRONG&gt; → outbound inspection está ativa&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Issuer = CA pública do site&lt;/STRONG&gt; → bypass/sem inspeção/escopo errado&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Erro de certificado&lt;/STRONG&gt; → problema de trust chain no endpoint&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Boa prática TAC:&lt;/STRONG&gt; teste em &lt;STRONG&gt;2 browsers&lt;/STRONG&gt; (Chrome/Edge e Firefox). Firefox pode usar store próprio dependendo do cenário.&lt;/P&gt;
&lt;H2&gt;1.2 Confirme trust da CA do gateway/CA interna&lt;/H2&gt;
&lt;P&gt;A &lt;STRONG&gt;CA do gateway&lt;/STRONG&gt; deve estar confiável no endpoint:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Windows:&lt;/STRONG&gt; &lt;EM&gt;Trusted Root Certification Authorities&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;macOS:&lt;/STRONG&gt; &lt;EM&gt;Keychain&lt;/EM&gt; (System)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Sinais típicos:&lt;/STRONG&gt; &lt;CODE&gt;NET::ERR_CERT_AUTHORITY_INVALID&lt;/CODE&gt;, alertas de chain, “connection not private”.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Evidência recomendada: &lt;STRONG&gt;screenshot&lt;/STRONG&gt; do certificado (Issuer/Subject/Validity) e do erro.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;2) Outbound vs Inbound (muita falha nasce aqui)&lt;/H1&gt;
&lt;H2&gt;2.1 Outbound inspection&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Requer a &lt;STRONG&gt;CA do gateway&lt;/STRONG&gt; confiável no endpoint.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;O gateway reassina certificados dinamicamente.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;2.2 Inbound inspection (serviços publicados)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Requer que o certificado do servidor (e chave privada correspondente, quando aplicável ao método) esteja &lt;STRONG&gt;importado/associado corretamente&lt;/STRONG&gt; no fluxo de certificados da inspeção (SmartConsole → HTTPS Inspection → Certificates, conforme modelo do seu ambiente).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Sintoma comum: serviço interno publicado “quebra” somente quando inbound inspection é habilitada.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;3) QUIC ≠ Pinning (separe as causas)&lt;/H1&gt;
&lt;H2&gt;3.1 QUIC/HTTP3 (transporte)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;QUIC/HTTP3 usa &lt;STRONG&gt;UDP/443&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Pode causar comportamento diferente do TCP/443 e atrapalhar troubleshooting.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Teste TAC (isolamento):&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Bloqueie &lt;STRONG&gt;UDP/443&lt;/STRONG&gt; temporariamente (força TCP/443) e compare:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;se “resolve”, você isolou QUIC como variável.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;se “não muda”, prossiga.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;3.2 Certificate pinning (mecanismo do app)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;O app valida um certificado/CA esperado e recusa a CA do gateway.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Sintoma: quebra consistente em &lt;STRONG&gt;domínios específicos&lt;/STRONG&gt; (não “a internet inteira”).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Tratamento TAC:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Bypass por domínio&lt;/STRONG&gt; (escopo mínimo + governança: owner/justificativa/review date).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Evite bypass global.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;4) Nota crítica: proxy explícito/autenticado e SSL inspection upstream&lt;/H1&gt;
&lt;P&gt;Se há &lt;STRONG&gt;proxy explícito&lt;/STRONG&gt;, &lt;STRONG&gt;proxy autenticado&lt;/STRONG&gt;, &lt;STRONG&gt;PAC&lt;/STRONG&gt; ou &lt;STRONG&gt;SSL inspection upstream&lt;/STRONG&gt;, você pode ter:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;reescrita de certificado (dupla inspeção → sintomas “parecidos com trust failure”)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;loops de autenticação&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;timeouts e resets em pico&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;comportamento inconsistente por grupo/subnet (PAC)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;TAC tip:&lt;/STRONG&gt; compare o mesmo teste em:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;rede corporativa (com proxy/PAC) &lt;STRONG&gt;vs&lt;/STRONG&gt; hotspot/4G (sem proxy)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;5) Tabela TAC de triagem rápida (Sintoma → Prova → Ação)&lt;/H1&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;Sintoma&lt;/TH&gt;
&lt;TH&gt;Causa provável&lt;/TH&gt;
&lt;TH&gt;Como provar (evidência)&lt;/TH&gt;
&lt;TH&gt;Ação recomendada&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Erro de certificado no browser&lt;/TD&gt;
&lt;TD&gt;CA do gateway não confiável&lt;/TD&gt;
&lt;TD&gt;Issuer não confiável / screenshot&lt;/TD&gt;
&lt;TD&gt;Distribuir CA via GPO/MDM; validar stores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;“Não inspeciona” (Issuer público)&lt;/TD&gt;
&lt;TD&gt;bypass/escopo/limitação&lt;/TD&gt;
&lt;TD&gt;certificado visto no client + regra/objeto&lt;/TD&gt;
&lt;TD&gt;revisar policy/ordem; procurar bypass inesperado&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;App/domínio específico quebra&lt;/TD&gt;
&lt;TD&gt;pinning/mTLS/requisitos&lt;/TD&gt;
&lt;TD&gt;falha sempre no mesmo domínio&lt;/TD&gt;
&lt;TD&gt;bypass por domínio com governança&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Intermitente (Chrome/Edge)&lt;/TD&gt;
&lt;TD&gt;QUIC/HTTP3&lt;/TD&gt;
&lt;TD&gt;bloqueia UDP/443 e compara&lt;/TD&gt;
&lt;TD&gt;manter UDP/443 bloqueado ou tratar exceções&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Lento após habilitar&lt;/TD&gt;
&lt;TD&gt;CPU/crypto/handshake sob carga&lt;/TD&gt;
&lt;TD&gt;cpview + correlação de horário&lt;/TD&gt;
&lt;TD&gt;rollout gradual; tuning e capacidade&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Funciona no 4G mas não na corp&lt;/TD&gt;
&lt;TD&gt;proxy/PAC/SSL upstream&lt;/TD&gt;
&lt;TD&gt;diferença de comportamento&lt;/TD&gt;
&lt;TD&gt;ajustar proxy/SSL upstream, trust chain&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;6) Logs: onde olhar e como extrair evidência&lt;/H1&gt;
&lt;H2&gt;6.1 Logs principais&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;$FWDIR/log/wstlsd.elg*&lt;/CODE&gt;&lt;/STRONG&gt; (TLS handshake / inspeção)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;/var/log/messages&lt;/CODE&gt;&lt;/STRONG&gt; (daemon/system errors)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;SmartLog/Logs no Management (eventos correlacionáveis)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;6.2 Acompanhar em tempo real (útil durante reprodução)&lt;/H2&gt;
&lt;PRE&gt;&lt;CODE class="language-bash"&gt;tail -f $FWDIR/log/wstlsd.elg*
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;H2&gt;6.3 “Padrões” úteis para buscar no &lt;CODE&gt;wstlsd.elg*&lt;/CODE&gt;&lt;/H2&gt;
&lt;P&gt;Sempre correlacione com o &lt;STRONG&gt;timestamp exato&lt;/STRONG&gt; do teste.&lt;/P&gt;
&lt;P&gt;Exemplos do que procurar (em termos práticos):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Handshake failure / negotiation mismatch&lt;/STRONG&gt; (versão/cipher/protocolo)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Certificate validation failures&lt;/STRONG&gt; (chain/trust/tempo/OCSP/CRL)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Timeouts / resets&lt;/STRONG&gt; para destinos específicos (padrão de incompatibilidade)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Bypass inesperado&lt;/STRONG&gt; (quando o tráfego não está sendo interceptado como esperado)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Importante: marque o horário do teste e filtre o log por janela (ex.: “últimos 5–10 minutos”) para reduzir ruído.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;7) Debug avançado do &lt;CODE&gt;wstlsd&lt;/CODE&gt; (quando você já isolou a camada)&lt;/H1&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Aviso TAC:&lt;/STRONG&gt; alto volume de logs e impacto potencial. Faça em janela.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;7.1 START (habilitar debug em todos os PIDs do wstlsd)&lt;/H2&gt;
&lt;PRE&gt;&lt;CODE class="language-bash"&gt;for PROC in $(pidof wstlsd); do fw debug $PROC on TDERROR_ALL_ALL=5; done
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Reproduza o problema (anote &lt;STRONG&gt;URL + timestamp&lt;/STRONG&gt;).&lt;/P&gt;
&lt;H2&gt;7.2 STOP (corrigido, completo)&lt;/H2&gt;
&lt;PRE&gt;&lt;CODE class="language-bash"&gt;for PROC in $(pidof wstlsd); do fw debug $PROC off TDERROR_ALL_ALL=0; done
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;H2&gt;7.3 Coleta mínima pós-debug&lt;/H2&gt;
&lt;PRE&gt;&lt;CODE class="language-bash"&gt;tail -n 2000 $FWDIR/log/wstlsd.elg* &amp;gt; /var/log/wstlsd_last2k.txt
tail -n 2000 /var/log/messages &amp;gt; /var/log/messages_last2k.txt
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;8)&lt;/img&gt; Boas práticas operacionais (o que evita incidentes)&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Rollout gradual&lt;/STRONG&gt; (pilot → waves) com KPIs: tickets, falhas, performance.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Governança de exceções&lt;/STRONG&gt;: owner + justificativa + review date + registro em change control (planilha/sistema).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Mudança única por vez&lt;/STRONG&gt; e documentação para rollback.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Auditar bypass&lt;/STRONG&gt; periodicamente para detectar “exceções esquecidas”.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Em ambientes com proxy: documentar e validar &lt;STRONG&gt;cadeia completa&lt;/STRONG&gt; e evitar &lt;STRONG&gt;dupla inspeção&lt;/STRONG&gt; quando possível.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;9) Template de coleta (para tópico CheckMates / TAC)&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Versão gateway + Jumbo take&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Browser(s) + versão (Chrome/Edge/Firefox)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;URL(s) + &lt;STRONG&gt;timestamp exato&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Sintoma (cert error / timeout / app quebra / lento / não inspeciona)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;CA do gateway instalada? (sim/não)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Método de distribuição da CA:&lt;/STRONG&gt; GPO / MDM / manual&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Ambiente usa &lt;STRONG&gt;proxy/PAC/autenticação&lt;/STRONG&gt;? (sim/não + detalhes)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;QUIC testado? &lt;STRONG&gt;bloqueou UDP/443?&lt;/STRONG&gt; (sim/não + resultado)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Logs: trecho de &lt;CODE&gt;wstlsd.elg*&lt;/CODE&gt; na janela do teste + &lt;CODE&gt;/var/log/messages&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2&gt;Referências oficiais (links diretos)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;sk108202 — Best Practices — HTTPS Inspection&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108202" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108202&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;sk112066 — How to troubleshoot an HTTPS Inspection issue&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk112066" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112066&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;sk111754 — QUIC/HTTP3 considerations with HTTPS Inspection (UDP/443)&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk111754" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk111754&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;sk163595 — Updatable object / bypass list (serviços com incompatibilidades/pinning)&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk163595" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk163595&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 06 Apr 2026 21:09:22 GMT</pubDate>
    <dc:creator>WiliRGasparetto</dc:creator>
    <dc:date>2026-04-06T21:09:22Z</dc:date>
    <item>
      <title>HTTPS Inspection Troubleshooting  Runbook por evidência (CA, QUIC, pinning, proxy e debug wstlsd)</title>
      <link>https://community.checkpoint.com/t5/Brazil/HTTPS-Inspection-Troubleshooting-Runbook-por-evid%C3%AAncia-CA-QUIC/m-p/274939#M52</link>
      <description>&lt;H2&gt;&lt;STRONG&gt; HTTPS Inspection Troubleshooting&amp;nbsp; Runbook por evidência (CA, QUIC, pinning, proxy e debug wstlsd)&lt;/STRONG&gt;&lt;/H2&gt;
&lt;H3&gt;Tese (como fechar RCA rápido)&lt;/H3&gt;
&lt;P&gt;Quando HTTPS Inspection “quebra”, &lt;STRONG&gt;não é um problema único&lt;/STRONG&gt;. Em campo, quase sempre cai em um destes blocos:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Trust chain no endpoint&lt;/STRONG&gt; (CA do gateway/CA interna não confiável)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Aplicação incompatível&lt;/STRONG&gt; (certificate pinning, mTLS, requisitos específicos)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Transporte fora do esperado&lt;/STRONG&gt; (&lt;STRONG&gt;QUIC/HTTP3 via UDP/443&lt;/STRONG&gt;)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Interferência de rede&lt;/STRONG&gt; (proxy explícito/autenticado, PAC, SSL inspection upstream)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Capacidade/handshake sob carga&lt;/STRONG&gt; (CPU/crypto, picos, perfil agressivo)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Bypass inesperado&lt;/STRONG&gt; (regra/objeto updatable/limitação) → “parece que não inspeciona”&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Regra TAC:&lt;/STRONG&gt; só mude configuração depois de coletar evidência mínima e isolar a variável (uma mudança por vez).&lt;/P&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;0) AVISOS TAC (impacto operacional e governança)&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;Antes de qualquer alteração (principalmente bypass e debug):&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Faça &lt;STRONG&gt;backup&lt;/STRONG&gt; do estado/configuração (e documente o baseline do que será alterado).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Execute em &lt;STRONG&gt;janela controlada&lt;/STRONG&gt;, preferencialmente com &lt;STRONG&gt;console&lt;/STRONG&gt; disponível.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Documente cada mudança&lt;/STRONG&gt; (para facilitar rollback).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Se for &lt;STRONG&gt;cluster&lt;/STRONG&gt;, planeje a coleta em &lt;STRONG&gt;todos os membros&lt;/STRONG&gt;, porque a falha/handshake pode ocorrer em qualquer nó.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;1) Fast triage em 10 minutos (sem debug)&lt;/H1&gt;
&lt;H2&gt;1.1 Confirme enforcement no cliente (prova mais rápida)&lt;/H2&gt;
&lt;P&gt;No browser, abra um site HTTPS e verifique o certificado apresentado:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Issuer = CA do gateway / CA interna&lt;/STRONG&gt; → outbound inspection está ativa&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Issuer = CA pública do site&lt;/STRONG&gt; → bypass/sem inspeção/escopo errado&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Erro de certificado&lt;/STRONG&gt; → problema de trust chain no endpoint&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Boa prática TAC:&lt;/STRONG&gt; teste em &lt;STRONG&gt;2 browsers&lt;/STRONG&gt; (Chrome/Edge e Firefox). Firefox pode usar store próprio dependendo do cenário.&lt;/P&gt;
&lt;H2&gt;1.2 Confirme trust da CA do gateway/CA interna&lt;/H2&gt;
&lt;P&gt;A &lt;STRONG&gt;CA do gateway&lt;/STRONG&gt; deve estar confiável no endpoint:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Windows:&lt;/STRONG&gt; &lt;EM&gt;Trusted Root Certification Authorities&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;macOS:&lt;/STRONG&gt; &lt;EM&gt;Keychain&lt;/EM&gt; (System)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Sinais típicos:&lt;/STRONG&gt; &lt;CODE&gt;NET::ERR_CERT_AUTHORITY_INVALID&lt;/CODE&gt;, alertas de chain, “connection not private”.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Evidência recomendada: &lt;STRONG&gt;screenshot&lt;/STRONG&gt; do certificado (Issuer/Subject/Validity) e do erro.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;2) Outbound vs Inbound (muita falha nasce aqui)&lt;/H1&gt;
&lt;H2&gt;2.1 Outbound inspection&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Requer a &lt;STRONG&gt;CA do gateway&lt;/STRONG&gt; confiável no endpoint.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;O gateway reassina certificados dinamicamente.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;2.2 Inbound inspection (serviços publicados)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Requer que o certificado do servidor (e chave privada correspondente, quando aplicável ao método) esteja &lt;STRONG&gt;importado/associado corretamente&lt;/STRONG&gt; no fluxo de certificados da inspeção (SmartConsole → HTTPS Inspection → Certificates, conforme modelo do seu ambiente).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Sintoma comum: serviço interno publicado “quebra” somente quando inbound inspection é habilitada.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;3) QUIC ≠ Pinning (separe as causas)&lt;/H1&gt;
&lt;H2&gt;3.1 QUIC/HTTP3 (transporte)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;QUIC/HTTP3 usa &lt;STRONG&gt;UDP/443&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Pode causar comportamento diferente do TCP/443 e atrapalhar troubleshooting.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Teste TAC (isolamento):&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Bloqueie &lt;STRONG&gt;UDP/443&lt;/STRONG&gt; temporariamente (força TCP/443) e compare:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;se “resolve”, você isolou QUIC como variável.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;se “não muda”, prossiga.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;3.2 Certificate pinning (mecanismo do app)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;O app valida um certificado/CA esperado e recusa a CA do gateway.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Sintoma: quebra consistente em &lt;STRONG&gt;domínios específicos&lt;/STRONG&gt; (não “a internet inteira”).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Tratamento TAC:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Bypass por domínio&lt;/STRONG&gt; (escopo mínimo + governança: owner/justificativa/review date).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Evite bypass global.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;4) Nota crítica: proxy explícito/autenticado e SSL inspection upstream&lt;/H1&gt;
&lt;P&gt;Se há &lt;STRONG&gt;proxy explícito&lt;/STRONG&gt;, &lt;STRONG&gt;proxy autenticado&lt;/STRONG&gt;, &lt;STRONG&gt;PAC&lt;/STRONG&gt; ou &lt;STRONG&gt;SSL inspection upstream&lt;/STRONG&gt;, você pode ter:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;reescrita de certificado (dupla inspeção → sintomas “parecidos com trust failure”)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;loops de autenticação&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;timeouts e resets em pico&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;comportamento inconsistente por grupo/subnet (PAC)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;TAC tip:&lt;/STRONG&gt; compare o mesmo teste em:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;rede corporativa (com proxy/PAC) &lt;STRONG&gt;vs&lt;/STRONG&gt; hotspot/4G (sem proxy)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;5) Tabela TAC de triagem rápida (Sintoma → Prova → Ação)&lt;/H1&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;Sintoma&lt;/TH&gt;
&lt;TH&gt;Causa provável&lt;/TH&gt;
&lt;TH&gt;Como provar (evidência)&lt;/TH&gt;
&lt;TH&gt;Ação recomendada&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Erro de certificado no browser&lt;/TD&gt;
&lt;TD&gt;CA do gateway não confiável&lt;/TD&gt;
&lt;TD&gt;Issuer não confiável / screenshot&lt;/TD&gt;
&lt;TD&gt;Distribuir CA via GPO/MDM; validar stores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;“Não inspeciona” (Issuer público)&lt;/TD&gt;
&lt;TD&gt;bypass/escopo/limitação&lt;/TD&gt;
&lt;TD&gt;certificado visto no client + regra/objeto&lt;/TD&gt;
&lt;TD&gt;revisar policy/ordem; procurar bypass inesperado&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;App/domínio específico quebra&lt;/TD&gt;
&lt;TD&gt;pinning/mTLS/requisitos&lt;/TD&gt;
&lt;TD&gt;falha sempre no mesmo domínio&lt;/TD&gt;
&lt;TD&gt;bypass por domínio com governança&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Intermitente (Chrome/Edge)&lt;/TD&gt;
&lt;TD&gt;QUIC/HTTP3&lt;/TD&gt;
&lt;TD&gt;bloqueia UDP/443 e compara&lt;/TD&gt;
&lt;TD&gt;manter UDP/443 bloqueado ou tratar exceções&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Lento após habilitar&lt;/TD&gt;
&lt;TD&gt;CPU/crypto/handshake sob carga&lt;/TD&gt;
&lt;TD&gt;cpview + correlação de horário&lt;/TD&gt;
&lt;TD&gt;rollout gradual; tuning e capacidade&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Funciona no 4G mas não na corp&lt;/TD&gt;
&lt;TD&gt;proxy/PAC/SSL upstream&lt;/TD&gt;
&lt;TD&gt;diferença de comportamento&lt;/TD&gt;
&lt;TD&gt;ajustar proxy/SSL upstream, trust chain&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;6) Logs: onde olhar e como extrair evidência&lt;/H1&gt;
&lt;H2&gt;6.1 Logs principais&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;$FWDIR/log/wstlsd.elg*&lt;/CODE&gt;&lt;/STRONG&gt; (TLS handshake / inspeção)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;/var/log/messages&lt;/CODE&gt;&lt;/STRONG&gt; (daemon/system errors)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;SmartLog/Logs no Management (eventos correlacionáveis)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;6.2 Acompanhar em tempo real (útil durante reprodução)&lt;/H2&gt;
&lt;PRE&gt;&lt;CODE class="language-bash"&gt;tail -f $FWDIR/log/wstlsd.elg*
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;H2&gt;6.3 “Padrões” úteis para buscar no &lt;CODE&gt;wstlsd.elg*&lt;/CODE&gt;&lt;/H2&gt;
&lt;P&gt;Sempre correlacione com o &lt;STRONG&gt;timestamp exato&lt;/STRONG&gt; do teste.&lt;/P&gt;
&lt;P&gt;Exemplos do que procurar (em termos práticos):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Handshake failure / negotiation mismatch&lt;/STRONG&gt; (versão/cipher/protocolo)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Certificate validation failures&lt;/STRONG&gt; (chain/trust/tempo/OCSP/CRL)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Timeouts / resets&lt;/STRONG&gt; para destinos específicos (padrão de incompatibilidade)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Bypass inesperado&lt;/STRONG&gt; (quando o tráfego não está sendo interceptado como esperado)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Importante: marque o horário do teste e filtre o log por janela (ex.: “últimos 5–10 minutos”) para reduzir ruído.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;7) Debug avançado do &lt;CODE&gt;wstlsd&lt;/CODE&gt; (quando você já isolou a camada)&lt;/H1&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Aviso TAC:&lt;/STRONG&gt; alto volume de logs e impacto potencial. Faça em janela.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;7.1 START (habilitar debug em todos os PIDs do wstlsd)&lt;/H2&gt;
&lt;PRE&gt;&lt;CODE class="language-bash"&gt;for PROC in $(pidof wstlsd); do fw debug $PROC on TDERROR_ALL_ALL=5; done
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Reproduza o problema (anote &lt;STRONG&gt;URL + timestamp&lt;/STRONG&gt;).&lt;/P&gt;
&lt;H2&gt;7.2 STOP (corrigido, completo)&lt;/H2&gt;
&lt;PRE&gt;&lt;CODE class="language-bash"&gt;for PROC in $(pidof wstlsd); do fw debug $PROC off TDERROR_ALL_ALL=0; done
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;H2&gt;7.3 Coleta mínima pós-debug&lt;/H2&gt;
&lt;PRE&gt;&lt;CODE class="language-bash"&gt;tail -n 2000 $FWDIR/log/wstlsd.elg* &amp;gt; /var/log/wstlsd_last2k.txt
tail -n 2000 /var/log/messages &amp;gt; /var/log/messages_last2k.txt
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;8)&lt;/img&gt; Boas práticas operacionais (o que evita incidentes)&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Rollout gradual&lt;/STRONG&gt; (pilot → waves) com KPIs: tickets, falhas, performance.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Governança de exceções&lt;/STRONG&gt;: owner + justificativa + review date + registro em change control (planilha/sistema).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Mudança única por vez&lt;/STRONG&gt; e documentação para rollback.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Auditar bypass&lt;/STRONG&gt; periodicamente para detectar “exceções esquecidas”.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Em ambientes com proxy: documentar e validar &lt;STRONG&gt;cadeia completa&lt;/STRONG&gt; e evitar &lt;STRONG&gt;dupla inspeção&lt;/STRONG&gt; quando possível.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;9) Template de coleta (para tópico CheckMates / TAC)&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Versão gateway + Jumbo take&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Browser(s) + versão (Chrome/Edge/Firefox)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;URL(s) + &lt;STRONG&gt;timestamp exato&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Sintoma (cert error / timeout / app quebra / lento / não inspeciona)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;CA do gateway instalada? (sim/não)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Método de distribuição da CA:&lt;/STRONG&gt; GPO / MDM / manual&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Ambiente usa &lt;STRONG&gt;proxy/PAC/autenticação&lt;/STRONG&gt;? (sim/não + detalhes)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;QUIC testado? &lt;STRONG&gt;bloqueou UDP/443?&lt;/STRONG&gt; (sim/não + resultado)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Logs: trecho de &lt;CODE&gt;wstlsd.elg*&lt;/CODE&gt; na janela do teste + &lt;CODE&gt;/var/log/messages&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2&gt;Referências oficiais (links diretos)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;sk108202 — Best Practices — HTTPS Inspection&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108202" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108202&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;sk112066 — How to troubleshoot an HTTPS Inspection issue&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk112066" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112066&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;sk111754 — QUIC/HTTP3 considerations with HTTPS Inspection (UDP/443)&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk111754" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk111754&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;sk163595 — Updatable object / bypass list (serviços com incompatibilidades/pinning)&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk163595" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk163595&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 06 Apr 2026 21:09:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Brazil/HTTPS-Inspection-Troubleshooting-Runbook-por-evid%C3%AAncia-CA-QUIC/m-p/274939#M52</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-04-06T21:09:22Z</dc:date>
    </item>
  </channel>
</rss>

