<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Are proxy relevant when using https inspection in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Are-proxy-relevant-when-using-https-inspection/m-p/119970#M22294</link>
    <description>&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;We’re looking at enabling the HTTP/HTTPS proxy functionality of the gateway but we are debating if it’s really worth it.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;If you use HTTPS inspection, URL filtering and Application control, are you adding much in terms of security with using the gateway as an HTTP/HTTPS proxy?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;Just curious about the community’s thoughts on this?&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 31 May 2021 18:28:08 GMT</pubDate>
    <dc:creator>flachance</dc:creator>
    <dc:date>2021-05-31T18:28:08Z</dc:date>
    <item>
      <title>Are proxy relevant when using https inspection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-proxy-relevant-when-using-https-inspection/m-p/119970#M22294</link>
      <description>&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;We’re looking at enabling the HTTP/HTTPS proxy functionality of the gateway but we are debating if it’s really worth it.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;If you use HTTPS inspection, URL filtering and Application control, are you adding much in terms of security with using the gateway as an HTTP/HTTPS proxy?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;Just curious about the community’s thoughts on this?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 18:28:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-proxy-relevant-when-using-https-inspection/m-p/119970#M22294</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2021-05-31T18:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Are proxy relevant when using https inspection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-proxy-relevant-when-using-https-inspection/m-p/119975#M22296</link>
      <description>&lt;P&gt;Personally, I will say it depends how powerful your firewall is. From my experience, I would say https inspection adds 10-15% CPU usage.&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 19:21:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-proxy-relevant-when-using-https-inspection/m-p/119975#M22296</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-05-31T19:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: Are proxy relevant when using https inspection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-proxy-relevant-when-using-https-inspection/m-p/119983#M22297</link>
      <description>&lt;P&gt;My experience with Check Point gateway as a Webproxy ends up in using another specialized vendor for such a solution.&lt;/P&gt;
&lt;P&gt;You‘ll get only a little bit more security but the Check Point proxy feature has not so much functionality and some limitations:&lt;/P&gt;
&lt;P&gt;- some authentications are not working&lt;/P&gt;
&lt;P&gt;- throughput is bad (SecureXL problem with proxy&amp;nbsp;&lt;SPAN&gt;sk92482)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- NAT problematic in high traffic environments&lt;/P&gt;
&lt;P&gt;- no forward proxies possible (example: sent website A to upstream proxy A and website B to upstream proxy B)&lt;/P&gt;
&lt;P&gt;If you really need a proxy solution then go with a specialized product like SQUID or another one. If not using proxy you‘re fine and secure with your Check Point gateway and using all security features you mentioned.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110013" target="_blank" rel="noopener"&gt;How to configure Check Point Security Gateway as HTTP/HTTPS Proxy&lt;/A&gt;&amp;nbsp; shows most of the limitations and configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 18:18:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-proxy-relevant-when-using-https-inspection/m-p/119983#M22297</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-02T18:18:41Z</dc:date>
    </item>
  </channel>
</rss>

