<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic https inspection is not working in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9162#M1155</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a strange problem with https inspection. Something I am missing here and run out of options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R80.10 with appl/urlf/https inspection turned on. Enhanced ssl inspection is on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cat $FWDIR/boot/modules/fwkern.conf&lt;BR /&gt;enhanced_ssl_inspection=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https inspection policy:&lt;/P&gt;&lt;P&gt;my computer -&amp;gt; internal networks;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;any category; action: bypass&lt;/P&gt;&lt;P&gt;my computer -&amp;gt; internet;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;specific URLs; action bypass&lt;/P&gt;&lt;P&gt;my computer -&amp;gt; internet;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;any category; action: inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First problem - there are no inspect logs. Only bypass for first https inspection rule.&lt;/P&gt;&lt;P&gt;Because it is not inspected, in appl/urlf policy my traffic avoiding first rules and hitting last one - any -&amp;gt; internet; action allow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wstlsd.elg file contains only:&lt;/P&gt;&lt;P&gt;[26 Nov 8:39:04] wstlsd_init: Instance #0 of Daemon initiated successfully&lt;BR /&gt;[26 Nov 8:39:04] wstlsd_init: Instance #2 of Daemon initiated successfully&lt;BR /&gt;[26 Nov 8:39:04] wstlsd_init: Instance #4 of Daemon initiated successfully&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Nov 2018 08:56:25 GMT</pubDate>
    <dc:creator>abihsot__</dc:creator>
    <dc:date>2018-11-26T08:56:25Z</dc:date>
    <item>
      <title>https inspection is not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9162#M1155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a strange problem with https inspection. Something I am missing here and run out of options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R80.10 with appl/urlf/https inspection turned on. Enhanced ssl inspection is on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cat $FWDIR/boot/modules/fwkern.conf&lt;BR /&gt;enhanced_ssl_inspection=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https inspection policy:&lt;/P&gt;&lt;P&gt;my computer -&amp;gt; internal networks;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;any category; action: bypass&lt;/P&gt;&lt;P&gt;my computer -&amp;gt; internet;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;specific URLs; action bypass&lt;/P&gt;&lt;P&gt;my computer -&amp;gt; internet;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;any category; action: inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First problem - there are no inspect logs. Only bypass for first https inspection rule.&lt;/P&gt;&lt;P&gt;Because it is not inspected, in appl/urlf policy my traffic avoiding first rules and hitting last one - any -&amp;gt; internet; action allow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wstlsd.elg file contains only:&lt;/P&gt;&lt;P&gt;[26 Nov 8:39:04] wstlsd_init: Instance #0 of Daemon initiated successfully&lt;BR /&gt;[26 Nov 8:39:04] wstlsd_init: Instance #2 of Daemon initiated successfully&lt;BR /&gt;[26 Nov 8:39:04] wstlsd_init: Instance #4 of Daemon initiated successfully&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2018 08:56:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9162#M1155</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2018-11-26T08:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection is not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9163#M1156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello. Please check your network topology. You must be sure that you have an 'external' interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2018 10:30:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9163#M1156</guid>
      <dc:creator>Evgeniy_Olkov</dc:creator>
      <dc:date>2018-11-26T10:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection is not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9164#M1157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you for suggestion! However I thought about this too, so I modified my https inspection policy to:&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;my computer -&amp;gt; internal networks;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;any category; action: bypass&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;my computer -&amp;gt; any;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;specific URLs; action bypass&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;my computer -&amp;gt; any;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;any category; action: inspect&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Still no luck.&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;By the way in firewall topology I have external interface defined.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2018 11:38:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9164#M1157</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2018-11-26T11:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection is not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9165#M1158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I mean the firewall network topology. I had the same&amp;nbsp;isue two weeks ago. After many actions I have just reconfigured the topology (override - External -&amp;gt; Internet) and installed the policy. And it has started to work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2018 11:44:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9165#M1158</guid>
      <dc:creator>Evgeniy_Olkov</dc:creator>
      <dc:date>2018-11-26T11:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection is not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9166#M1159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wanted to let you know that after removing identity awareness object from https inspection policy it started working... However I am still not happy how it works. I'll do some more testing&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2018 07:04:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-inspection-is-not-working/m-p/9166#M1159</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2018-12-28T07:04:25Z</dc:date>
    </item>
  </channel>
</rss>

