<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection Rule Not Being Matched in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130724#M23770</link>
    <description>&lt;P&gt;Just answered my own question.&lt;/P&gt;&lt;P&gt;Changed the URL in the object to "&lt;SPAN&gt;ase-dev.ourdomain.com" (not regex) and inspection works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But will need upgrade to meet the requirements....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks PhoneBoy.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Sep 2021 15:11:54 GMT</pubDate>
    <dc:creator>Gerard2012</dc:creator>
    <dc:date>2021-09-30T15:11:54Z</dc:date>
    <item>
      <title>HTTPS Inspection Rule Not Being Matched</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130693#M23761</link>
      <description>&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In tried search forum for answer to this but nothing I've seen seems to work for me.&lt;/P&gt;&lt;P&gt;I'm have been tasked to enabled URL filtering to restrict access to internally hosted web apps.&lt;/P&gt;&lt;P&gt;I have enabled HTTPS inspection and have successfully blocked access to external HTTPS sites as a test, but for some reason the URL for this internal app is not matched in the inspection rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this instance the CP software is R80.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The URL in question is:&lt;/P&gt;&lt;P&gt;&lt;A href="https://ukst-webapp-utils-dev009.ase-dev.ourdomain.com/clientapp" target="_blank"&gt;https://ukst-webapp-utils-dev009.ase-dev.ourdomain.com/clientapp&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried every iteration of this in the Custom Application object...&lt;/P&gt;&lt;P&gt;"ukst-webapp-utils-dev009.ase-dev.ourdomain.com/clientapp"&lt;/P&gt;&lt;P&gt;"ukst-webapp-utils-dev009.ase-dev.ourdomain.com"&lt;/P&gt;&lt;P&gt;"ase-dev.ourdomain.com"&lt;/P&gt;&lt;P&gt;As regex...&lt;/P&gt;&lt;P&gt;".*\.ase-dev\.ourdomain\.com\/clientapp"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It just will not hit the inspection rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The server presents a wildcard cert for "*.ase-dev.ourdomain.com", is that significant?&lt;/P&gt;&lt;P&gt;It only works when I set the rule site category to "any", and then traffic seems to be classified as "Business / Economy".&lt;/P&gt;&lt;P&gt;Any advise would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 13:45:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130693#M23761</guid>
      <dc:creator>Gerard2012</dc:creator>
      <dc:date>2021-09-30T13:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Rule Not Being Matched</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130697#M23763</link>
      <description>&lt;P&gt;In R80.10, we match only based on the DN of the certificate.&lt;BR /&gt;Later versions support SNI (possibly requiring a JHF).&lt;BR /&gt;In any case, R80.10 is nearly End of Support and recommend upgrading.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 13:50:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130697#M23763</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-30T13:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Rule Not Being Matched</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130723#M23769</link>
      <description>&lt;P&gt;Thanks for responding so quickly PhoneBoy.&lt;/P&gt;&lt;P&gt;Yes, noted this needs to be upgraded, but to clarify, is it at all possible to match an inspection rule for a wildcard cert? If the the&amp;nbsp;&lt;SPAN&gt;Custom Application object were just ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;".*\.ase-dev\.ourdomain\.com\"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;for example?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 15:06:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130723#M23769</guid>
      <dc:creator>Gerard2012</dc:creator>
      <dc:date>2021-09-30T15:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Rule Not Being Matched</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130724#M23770</link>
      <description>&lt;P&gt;Just answered my own question.&lt;/P&gt;&lt;P&gt;Changed the URL in the object to "&lt;SPAN&gt;ase-dev.ourdomain.com" (not regex) and inspection works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But will need upgrade to meet the requirements....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks PhoneBoy.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 15:11:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130724#M23770</guid>
      <dc:creator>Gerard2012</dc:creator>
      <dc:date>2021-09-30T15:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Rule Not Being Matched</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130733#M23771</link>
      <description>&lt;P&gt;I was just about to reply and suggest what you put in there. I ALWAYS use that method for allowing./blocking...*domain* and works fine : )&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 16:11:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-Rule-Not-Being-Matched/m-p/130733#M23771</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-30T16:11:55Z</dc:date>
    </item>
  </channel>
</rss>

