<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76270#M15480</link>
    <description>I believe so if SNI happens early enough in the negotiation that we can bypass it in this case.&lt;BR /&gt;Also, the SK does not mention R80.30, but it's worth double-checking.</description>
    <pubDate>Mon, 24 Feb 2020 22:10:23 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-02-24T22:10:23Z</dc:date>
    <item>
      <title>New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/75959#M15402</link>
      <description>&lt;P&gt;We are glad to share a new &lt;STRONG&gt;usability&lt;/STRONG&gt; enhancement for our &lt;STRONG&gt;HTTPS Inspection&lt;/STRONG&gt; customers.&lt;BR /&gt;Starting from &lt;STRONG&gt;R80.40&lt;/STRONG&gt;, HTTPS Inspection customers will be able to consolidate their &lt;A href="https://owasp.org/www-community/controls/Certificate_and_Public_Key_Pinning" target="_blank"&gt;certificate pinned&lt;/A&gt; apps rules using managed updatable objects.&lt;/P&gt;
&lt;P&gt;We've collected a list of HTTPS services which are known to be used in scenarios where HTTPS Inspection is unable to establish the trust between the client and the Security Gateway and is therefore unable to inspect the traffic.&lt;BR /&gt;These HTTPS services are part of &lt;STRONG&gt;"HTTPS services - bypass"&lt;/STRONG&gt; updatable object.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="image001.png" style="width: 298px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4540i5C2497AA537065EA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image001.png" alt="image001.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You can choose to add this object to HTTPS Inspection policy as a bypass rule to avoid connectivity issues and/or to the Access policy as a drop rule to block these services explicitly.&lt;BR /&gt;&lt;STRONG&gt;For further information please refer to &lt;/STRONG&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk163595" target="_blank"&gt;sk163595&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you'd like to see some additional services added to this, let us know!&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 23:52:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/75959#M15402</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-20T23:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/75960#M15403</link>
      <description>&lt;P&gt;Thanks Check Point!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 00:38:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/75960#M15403</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-02-21T00:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76055#M15424</link>
      <description>&lt;P&gt;Please tell me what is the difference between HTTPS Whitelisting and&amp;nbsp;HTTPS Services Bypass ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2020 08:38:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76055#M15424</guid>
      <dc:creator>RoD</dc:creator>
      <dc:date>2020-02-22T08:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76066#M15427</link>
      <description>&lt;P&gt;&amp;nbsp;Thanks for insight.&amp;nbsp;&amp;nbsp;&amp;nbsp; Are there plans to ADD this to R80.30 as part of future JHA jumbo update?&lt;/P&gt;&lt;P&gt;thanks -GA&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2020 15:52:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76066#M15427</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2020-02-22T15:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76076#M15433</link>
      <description>Use of Updatable Objects in the HTTPS Inspection policy required some major infrastructure improvements.&lt;BR /&gt;I don't believe these will be backported to earlier releases.</description>
      <pubDate>Sat, 22 Feb 2020 20:31:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76076#M15433</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-22T20:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76077#M15434</link>
      <description>The HTTPS Inspection policy determines what traffic is "man in the middled" so you can see and make security decisions on the unencrypted contents.&lt;BR /&gt;The actions for the rules in that rulebase are either "Inspect" or "Bypass."&lt;BR /&gt;Not sure where whitelisting enters into the discussion.</description>
      <pubDate>Sat, 22 Feb 2020 20:36:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76077#M15434</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-22T20:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76079#M15435</link>
      <description>&lt;P data-unlink="true"&gt;HTTPS Whitelisting is using also for bypass HTTPS inspection, if I want that&amp;nbsp;HTTPS inspection bypass some&amp;nbsp; domain like&amp;nbsp;goldmansachs.com &amp;nbsp;, what is a best way to bypass&amp;nbsp;HTTPS inspection for this domain, using&amp;nbsp;HTTPS Whitelisting or&amp;nbsp;HTTPS services - bypass ? Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2020 21:01:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76079#M15435</guid>
      <dc:creator>RoD</dc:creator>
      <dc:date>2020-02-22T21:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76093#M15440</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2020 00:19:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76093#M15440</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2020-02-23T00:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76098#M15441</link>
      <description>You create a custom application with the domain(s) you wish to bypass and add a rule for that domain in the HTTPS Inspection policy.&lt;BR /&gt;The "whitelist" that document refers to is one we maintain and cannot be updated by you.</description>
      <pubDate>Sun, 23 Feb 2020 02:12:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76098#M15441</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-23T02:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76109#M15446</link>
      <description>&lt;P&gt;OK, Thank you&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2020 08:14:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76109#M15446</guid>
      <dc:creator>RoD</dc:creator>
      <dc:date>2020-02-23T08:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76121#M15453</link>
      <description>Hi, &lt;BR /&gt;Adding support for updatable objects in R80.30 releases won't be possible, the support for for updatable objects requires the new HTTPS Inspection policy that was embedded to the SmartConsole, and this change is to big and complicated for the jumbo releases.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 23 Feb 2020 14:16:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76121#M15453</guid>
      <dc:creator>Uriel_F</dc:creator>
      <dc:date>2020-02-23T14:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76123#M15454</link>
      <description>&lt;P&gt;thanks for the insight!&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2020 16:28:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76123#M15454</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2020-02-23T16:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76133#M15455</link>
      <description>&lt;P&gt;This is a positive update for HTTPS inspection thanks!&lt;/P&gt;&lt;P&gt;Are there any improvements where a client certificate is used? Right now on R80.30 we have to add a bypass rule by IP address in rule position #1 to allow client cert to work. Being able to do this by domain name would be a huge benefit (especially when the application is hosted in AWS/Azure!)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2020 23:09:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76133#M15455</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-02-23T23:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76140#M15456</link>
      <description>I don’t believe any vendor handles TLS Client Auth very well.&lt;BR /&gt;Sites that require this must be bypassed.&lt;BR /&gt;You can create a custom application definition with the domain in question and use that in the rule—should work in R80.30.</description>
      <pubDate>Mon, 24 Feb 2020 01:18:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76140#M15456</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-24T01:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76168#M15461</link>
      <description>&lt;P&gt;You can try to reference sk165094 (&lt;STRONG&gt;Custom Applications/Sites&lt;/STRONG&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt; - Best practice).&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 10:30:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76168#M15461</guid>
      <dc:creator>RickLin</dc:creator>
      <dc:date>2020-02-24T10:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76210#M15467</link>
      <description>&lt;P&gt;Will this eventually include the O365 'Optimize' category from their RSS feed to bypass HTTPS inspection?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference article:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/archive/blogs/onthewire/new-office-365-url-categories-to-help-you-optimize-the-traffic-which-really-matters" target="_blank"&gt;https://docs.microsoft.com/en-us/archive/blogs/onthewire/new-office-365-url-categories-to-help-you-optimize-the-traffic-which-really-matters&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 14:39:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76210#M15467</guid>
      <dc:creator>Joseph_Audet</dc:creator>
      <dc:date>2020-02-24T14:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76214#M15468</link>
      <description>&lt;P&gt;I think it is a good idea, but the question should be directed to R&amp;amp;D&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 14:50:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76214#M15468</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-02-24T14:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76267#M15477</link>
      <description>&lt;P&gt;Has&amp;nbsp;sk66405 been officially "fixed"? I guess it depends on whether the client cert based application supports SNI or not as to whether we can bypass by domain name.&lt;/P&gt;&lt;P&gt;I might have to setup a test server and give it a try.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 22:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76267#M15477</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-02-24T22:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76270#M15480</link>
      <description>I believe so if SNI happens early enough in the negotiation that we can bypass it in this case.&lt;BR /&gt;Also, the SK does not mention R80.30, but it's worth double-checking.</description>
      <pubDate>Mon, 24 Feb 2020 22:10:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76270#M15480</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-24T22:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: New updatable object for HTTPS Inspection: HTTPS Services Bypass</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76291#M15485</link>
      <description>&lt;P&gt;Just curious, what is to fix in&amp;nbsp;&lt;SPAN&gt;sk66405,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14416"&gt;@Ryan_Ryan&lt;/a&gt;. The SK says, client certificates are not supported with HTTPSi&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 07:27:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-updatable-object-for-HTTPS-Inspection-HTTPS-Services-Bypass/m-p/76291#M15485</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-02-25T07:27:32Z</dc:date>
    </item>
  </channel>
</rss>

