<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issues between Checkpoint FW and ESET antivirus in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Issues-between-Checkpoint-FW-and-ESET-antivirus/m-p/124370#M22989</link>
    <description>&lt;P&gt;Hello everyone.&lt;/P&gt;&lt;P&gt;We have issues &lt;STRONG&gt;some&lt;/STRONG&gt; websites. Our perimeter FW is&lt;/P&gt;&lt;P&gt;R80.40, standalone&lt;BR /&gt;Blades FW, APPC, URLF, IPS, AV, AB, TE and IA. Besides HTTPS INSPECTION enabled.&lt;BR /&gt;In windows hosts:&lt;/P&gt;&lt;P&gt;ESET endpoint security with Filter SSL/TLS functionality enabled (same as https inspection).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Issues: some websites load first time in web browser (edge, firefox, chrome), but in second time don't load o take it long time (2-10minutes) to load. It's worth to mentioned if we delete cookies in web browser, trouble's websites load again without problems..only first time.&lt;/P&gt;&lt;P&gt;Workarounds:&lt;/P&gt;&lt;P&gt;Disable https inspection to such hosts (as source traffice) or to such websites (as destiny traffic)...or...&lt;BR /&gt;.... disable Eset Filter SSL/TLS on windows hosts, so&amp;nbsp;it is no longer need to disable the FW HTTPS Inspection&lt;BR /&gt;Above means that both CP Https Inspection and ESET Filter SSL/TLS can't work at same time&lt;STRONG&gt; to such websites&lt;/STRONG&gt;. Apparently cookies are tried or modified in some point in any way by unknown entity (for me), so&amp;nbsp; ESET antivirus o CP FW refuse to allow traffic.&lt;/P&gt;&lt;P&gt;I did contact ESET support. Solution them bring me was bypass such websites in eset antivirus, but I don't like this solution because&amp;nbsp;the number of websites is constantly growing, and over time I will end up with hundreds or thousands of bypassed websites, additional of security risks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did disable temporary threat prevention blades, so just enabled FW, APPC ad URLF, however problematic behavior persist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion before I contact checkpoint TAC support?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jul 2021 20:00:35 GMT</pubDate>
    <dc:creator>LuisSP</dc:creator>
    <dc:date>2021-07-19T20:00:35Z</dc:date>
    <item>
      <title>Issues between Checkpoint FW and ESET antivirus</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Issues-between-Checkpoint-FW-and-ESET-antivirus/m-p/124370#M22989</link>
      <description>&lt;P&gt;Hello everyone.&lt;/P&gt;&lt;P&gt;We have issues &lt;STRONG&gt;some&lt;/STRONG&gt; websites. Our perimeter FW is&lt;/P&gt;&lt;P&gt;R80.40, standalone&lt;BR /&gt;Blades FW, APPC, URLF, IPS, AV, AB, TE and IA. Besides HTTPS INSPECTION enabled.&lt;BR /&gt;In windows hosts:&lt;/P&gt;&lt;P&gt;ESET endpoint security with Filter SSL/TLS functionality enabled (same as https inspection).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Issues: some websites load first time in web browser (edge, firefox, chrome), but in second time don't load o take it long time (2-10minutes) to load. It's worth to mentioned if we delete cookies in web browser, trouble's websites load again without problems..only first time.&lt;/P&gt;&lt;P&gt;Workarounds:&lt;/P&gt;&lt;P&gt;Disable https inspection to such hosts (as source traffice) or to such websites (as destiny traffic)...or...&lt;BR /&gt;.... disable Eset Filter SSL/TLS on windows hosts, so&amp;nbsp;it is no longer need to disable the FW HTTPS Inspection&lt;BR /&gt;Above means that both CP Https Inspection and ESET Filter SSL/TLS can't work at same time&lt;STRONG&gt; to such websites&lt;/STRONG&gt;. Apparently cookies are tried or modified in some point in any way by unknown entity (for me), so&amp;nbsp; ESET antivirus o CP FW refuse to allow traffic.&lt;/P&gt;&lt;P&gt;I did contact ESET support. Solution them bring me was bypass such websites in eset antivirus, but I don't like this solution because&amp;nbsp;the number of websites is constantly growing, and over time I will end up with hundreds or thousands of bypassed websites, additional of security risks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did disable temporary threat prevention blades, so just enabled FW, APPC ad URLF, however problematic behavior persist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion before I contact checkpoint TAC support?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 20:00:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Issues-between-Checkpoint-FW-and-ESET-antivirus/m-p/124370#M22989</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2021-07-19T20:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Issues between Checkpoint FW and ESET antivirus</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Issues-between-Checkpoint-FW-and-ESET-antivirus/m-p/124374#M22990</link>
      <description>&lt;P&gt;Double HTTPS Inspection will probably cause some issues, particularly if you don’t install the relevant CA certificates as trusted in ESET and Check Point.&lt;BR /&gt;Anything in the logs that you can see or through packet capture?&lt;BR /&gt;TAC can certainly help with debugging HTTPS Inspection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 20:12:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Issues-between-Checkpoint-FW-and-ESET-antivirus/m-p/124374#M22990</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-19T20:12:22Z</dc:date>
    </item>
  </channel>
</rss>

