<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14584#M2489</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;as per sk92888 using the CP as a proxy would be a workaround when you disable probe bypass that doesn't seem to require two connections - at least there is no mention of a second connection being required. I'd hope/guess this is because the CONNECT request which presents the host in cleartext before any actual&amp;nbsp;tunnel gets built&lt;/P&gt;&lt;P&gt;Also check this&amp;nbsp;&lt;A href="https://community.checkpoint.com/message/12721-https-inspection-probe-bypass-to-enable-or-not-to-enable" target="_blank"&gt;https://community.checkpoint.com/message/12721-https-inspection-probe-bypass-to-enable-or-not-to-enable&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Jun 2019 09:04:43 GMT</pubDate>
    <dc:creator>Albert_Wilkes</dc:creator>
    <dc:date>2019-06-21T09:04:43Z</dc:date>
    <item>
      <title>Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14578#M2483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone, Customer now uses HTTPS inspection with probe bypass.&amp;nbsp;&lt;/P&gt;&lt;P&gt;He found that he could not access some website. After checked, those website site works only in browsers with SNI support.&lt;/P&gt;&lt;P&gt;I found the&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk104717 point that the l&lt;SPAN&gt;imitation of HTTPS Inspection Bypass Mechanism with enabled Probe Bypass is&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;HTTPS Inspection will not work for sites that require SNI extension in the SSL "Client hello" packet.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;I tried bypassing the URL of those websites but it still didn't work.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;Is there any workaround for it? Or Is there any future plan for fixing the issue?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Nov 2017 15:20:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14578#M2483</guid>
      <dc:creator>WAI_KIT_LAO</dc:creator>
      <dc:date>2017-11-27T15:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14579#M2484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We got the same issue. We are running R80.10. In order to take the advantages of the "unified" policy, we will need to turn on the Application/URL blades. In order to have the firewall detect the URL properly, the https decryption would be on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, there are a lot of sites using SNI, most common ones are hosts solutions since people more and more moved their sites to the cloud. It is very hard to do the pro bypass on those sites. In the end, we had to disable the https decryption because we got too many support calls to deal with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition, so called "ground up redesigned" R80.10 still stuck in the R77 https policy editor with no simple check box on decryption within the rules like the competitor Palo Alto.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Nov 2017 23:48:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14579#M2484</guid>
      <dc:creator>William_Chang</dc:creator>
      <dc:date>2017-11-27T23:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14580#M2485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SNI information is sent in plaintext, which makes it&amp;nbsp;trivial to spoof.&lt;/P&gt;&lt;P&gt;This makes using&amp;nbsp;SNI as the basis for a security decision unwise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, there is a clear need for this functionality and we are investigating how to address this in a secure way.&lt;/P&gt;&lt;P&gt;It's also something that may be resolved in the&amp;nbsp;TLS/1.3 spec.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 06:37:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14580#M2485</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-28T06:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14581#M2486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as blocking is concerned I would trust SNI. If the client indicates it wants to go somewhere where I have a simple match on a blocking rule I would call it day and block the connection.&lt;/P&gt;&lt;P&gt;On allow rules it becomes ..... complicated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 11:57:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14581#M2486</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-11-28T11:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14582#M2487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am looking forward Checkpoint improvement but does any workaround&amp;nbsp;for the SNI traffic now?&lt;/P&gt;&lt;P&gt;The customer doesn't want to disable the&amp;nbsp;HTTPS probe bypass because it can Stop the inspection of the first connection to bypassed sites.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2017 07:53:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14582#M2487</guid>
      <dc:creator>WAI_KIT_LAO</dc:creator>
      <dc:date>2017-11-29T07:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14583#M2488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to create an object with the website domain and the IP of this webservice and explicitly create a bypass rule for that object(s). You will have the issue again when the IP behind this website changes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Feb 2018 14:17:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14583#M2488</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2018-02-14T14:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14584#M2489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;as per sk92888 using the CP as a proxy would be a workaround when you disable probe bypass that doesn't seem to require two connections - at least there is no mention of a second connection being required. I'd hope/guess this is because the CONNECT request which presents the host in cleartext before any actual&amp;nbsp;tunnel gets built&lt;/P&gt;&lt;P&gt;Also check this&amp;nbsp;&lt;A href="https://community.checkpoint.com/message/12721-https-inspection-probe-bypass-to-enable-or-not-to-enable" target="_blank"&gt;https://community.checkpoint.com/message/12721-https-inspection-probe-bypass-to-enable-or-not-to-enable&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:04:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14584#M2489</guid>
      <dc:creator>Albert_Wilkes</dc:creator>
      <dc:date>2019-06-21T09:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14585#M2490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There&amp;nbsp;is&amp;nbsp;a fix coming in July for this issue (probe bypass with SNI) on top of R80.10.&lt;/P&gt;&lt;P&gt;To get it please contact your local SE and ask to open RFE ticket for solution center.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Apr 2018 10:42:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14585#M2490</guid>
      <dc:creator>Amos_Reiss</dc:creator>
      <dc:date>2018-04-15T10:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14586#M2491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Can you share more details about how the issue is solved?&lt;/P&gt;&lt;P class=""&gt;- automatic bypass of SNI?&lt;/P&gt;&lt;P class=""&gt;- working Probe Bypass with SNI?&lt;/P&gt;&lt;P class=""&gt;- or other solution I‘m not thinking about?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2018 16:42:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14586#M2491</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2018-04-19T16:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14587#M2492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; color: #1f497d;"&gt;We are going to move the rulebase decision to a later point in the connection when we are able to send the SNI and then cache would be including “verified” SNI. This should allow us to work with SNI in a secure manner.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Apr 2018 07:01:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14587#M2492</guid>
      <dc:creator>Amos_Reiss</dc:creator>
      <dc:date>2018-04-22T07:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14588#M2493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's good to hear that improvement from you.&lt;/P&gt;&lt;P&gt;Does the fix work for R77.30?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 10:58:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14588#M2493</guid>
      <dc:creator>WAI_KIT_LAO</dc:creator>
      <dc:date>2018-04-25T10:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14589#M2494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, only R80.10 and later versions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 11:32:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14589#M2494</guid>
      <dc:creator>Amos_Reiss</dc:creator>
      <dc:date>2018-04-25T11:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14590#M2495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now that we're past July, there's nothing in the R80.10 jumbo HFA notes (or other public SK articles that I could find) about an HTTPS inspection fix for probe bypass and SNI. I contacted my local SE a couple of times to clarify whether this is available but haven't got an answer. What is the status of this fix?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the fix is not available, &lt;SPAN style="font-size: 11.0pt;"&gt;what is the current “recommendation” about enabling probe bypass with HTTPS inspection (for both R77.30 and R80.10)? I can see why it would be a good thing (aside from the SNI issue), but it’s not recommended under the best practices SK article (sk108202, appearing only under troubleshooting).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Paul&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2018 07:10:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14590#M2495</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2018-08-17T07:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14591#M2496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SNI HF is released already but it is not part of Jumbo HF.&lt;/P&gt;&lt;P&gt;This is why you will need to contact your SE / Sales representative which should contact Solution Center.&lt;/P&gt;&lt;P&gt;We will&amp;nbsp; release it as part of JHF later on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Amos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 13:53:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14591#M2496</guid>
      <dc:creator>Amos_Reiss</dc:creator>
      <dc:date>2018-08-28T13:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14592#M2497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it still the case that this SNI hotfix is available for R80.10 only? And not for R77.30?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How about R80.20? Is this fix incorporated into the GA release, or is still an additional hotfix?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;—&lt;/P&gt;&lt;P&gt;Carey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 19:45:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14592#M2497</guid>
      <dc:creator>Carey_Page-Sinc</dc:creator>
      <dc:date>2018-10-16T19:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14593#M2498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Carey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R77.30 - No plans.&lt;/P&gt;&lt;P&gt;R80.20 GA don't have this code yet but we do plan to have a HF for it as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Amos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2018 08:44:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14593#M2498</guid>
      <dc:creator>Amos_Reiss</dc:creator>
      <dc:date>2018-10-17T08:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14594#M2499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I received the hotfix from our SE and installed today on top of take 103 of R80.10 as advised. The problem is now that disabling probe bypass causes all HTTPS inspection traffic to fail completely. With probe bypass enabled, attempting to bypass sites based on the 'Site/Category' column above the catch all inspect rule in the HTTPS inspection policy seems to cause all HTTPS sites to be bypassed for inspection. The exception to this is where the source and destination columns do not match the traffic for the bypass rule, and pass on to the catch all inspect rule. For example if you specify an IP in the destination field to be bypassed then traffic destined to other IPs will pass this rule in the inspection rulebase. Without a bypass rule inspection works fine. This seems to effectively have caused more problems. Is anyone else aware of similar symptoms?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2018 15:12:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14594#M2499</guid>
      <dc:creator>Robert_Gilbert</dc:creator>
      <dc:date>2018-10-17T15:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14595#M2500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Robert, please ask your SE to contact me to look into this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Amos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 06:24:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14595#M2500</guid>
      <dc:creator>Amos_Reiss</dc:creator>
      <dc:date>2018-10-18T06:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14596#M2501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any updates/feedback on the SNI hotfix? I'm planning on enabling probe bypass next week. I'm keen to hear if the SNI fix is something I should have ready to go if needed?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2018 07:44:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14596#M2501</guid>
      <dc:creator>Darran_Lebas</dc:creator>
      <dc:date>2018-10-26T07:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any workaround for SNI HTTPS traffic when enabled the HTTPS probe bypass?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14597#M2502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still having the same issues. I'm speaking with a Checkpoint engineer on Thursday so hopefully will have some progress then.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2018 14:34:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Is-there-any-workaround-for-SNI-HTTPS-traffic-when-enabled-the/m-p/14597#M2502</guid>
      <dc:creator>Robert_Gilbert</dc:creator>
      <dc:date>2018-10-29T14:34:21Z</dc:date>
    </item>
  </channel>
</rss>

