<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Integrate Firewalls and SSL Decryption in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/165100#M27523</link>
    <description>&lt;P&gt;If you are using F5 for load balancing, offload the TSL termination to the F5. I have several TLS-heavy customers that do this. I also see more and more dumping F5/Bluecoat/etc. as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;said, it's becoming too expensive, vs. moving up a gateway model.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Dec 2022 22:00:17 GMT</pubDate>
    <dc:creator>Jim_Holmes</dc:creator>
    <dc:date>2022-12-13T22:00:17Z</dc:date>
    <item>
      <title>How to Integrate Firewalls and SSL Decryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164900#M27501</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;We are going to change the configuration according to the customer's request.&lt;BR /&gt;SSL encryption and decryption is performed using F5, not Checkpoint Firewall, and 3rd party APT solution is integrated and operated.&lt;/P&gt;&lt;P&gt;Customers want to use Checkpoint's Prevention and Emulation feature instead of their existing APT solution.&lt;/P&gt;&lt;P&gt;As in the goal configuration diagram, the decryption traffic is again controlled by the checkpoint firewall to control the threat traffic.&lt;/P&gt;&lt;P&gt;Can you tell me what problems are expected if I configure it according to the target configuration diagram?&lt;/P&gt;&lt;P&gt;I'd like to know if anyone has experience with a similar configuration like this.&lt;/P&gt;&lt;P&gt;I need your advice.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Outbound traffic flow :&lt;/P&gt;&lt;P&gt;1.encrypted traffic&lt;/P&gt;&lt;P&gt;2.Decryption traffic from F5 SSL&lt;/P&gt;&lt;P&gt;3.Detection and blocking by checkpoint threat prevention policy&lt;/P&gt;&lt;P&gt;4.Encrypted traffic from F5 SSL&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Diagram.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18757iAE8CC60C861B91FC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Diagram.PNG" alt="Diagram.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 01:04:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164900#M27501</guid>
      <dc:creator>ykpark</dc:creator>
      <dc:date>2022-12-13T01:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to Integrate Firewalls and SSL Decryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164903#M27502</link>
      <description>&lt;P&gt;Usually, when the Check Point gateway isn’t doing the SSL Decrypt/Encrypt, you have boxes doing that on the inside and outside versus routing the encrypt and decrypt through the same box.&lt;BR /&gt;This creates the possibility of “double inspection” on the same flow, which will be dropped by the gateway unless the F5 can change the traffic on the outbound after re-encrypting so it looks different to the Check Point device.&lt;BR /&gt;However, you’re also doubling the amount of traffic the gateway is passing as well, which can have sizing implications.&lt;/P&gt;
&lt;P&gt;The vast majority of customers just use our HTTPS Inspection instead of using an external SSL decrypt/reencrypt.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 01:24:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164903#M27502</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-13T01:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to Integrate Firewalls and SSL Decryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164905#M27503</link>
      <description>&lt;P&gt;To add to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;comment, I spoke to customers in last 2-3 years who actually abandoned 3rd party vendors they were using specifically for ssl decryption (ie Bluecoat), as it was getting expensive and they went with CP https inspection, as it makes more sense, since you can use it as a blade on already existing firewall/cluster. I will say though, in all honesty, I was not a big fan of it back in R77.xx days, but it has come a long way since R80, for sure.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 01:40:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164905#M27503</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-13T01:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to Integrate Firewalls and SSL Decryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164906#M27504</link>
      <description>&lt;P&gt;Can you share some additional detail as to the configuration...&lt;/P&gt;
&lt;P&gt;Is the F5 proposed to be deployed as L2, L3 or using ICAP, doing NAT etc?&lt;/P&gt;
&lt;P&gt;Further to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;earlier comments refer&amp;nbsp;&lt;SPAN&gt;sk172204.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 02:20:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164906#M27504</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-13T02:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to Integrate Firewalls and SSL Decryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164908#M27505</link>
      <description>&lt;P&gt;Can I use cloud emulation when integrating with ICAP?&amp;nbsp; The firewall is NGTX.&lt;BR /&gt;I think it's the best way if this feature is provided.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 01:59:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164908#M27505</guid>
      <dc:creator>ykpark</dc:creator>
      <dc:date>2022-12-13T01:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to Integrate Firewalls and SSL Decryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164912#M27506</link>
      <description>&lt;P&gt;Please refer to the ICAP portion of the Threat Prevention admin guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ThreatPrevention_AdminGuide/Topics-TPG/ICAP_Server.htm?tocpath=ICAP%7CThe%20Security%20Gateway%20as%20an%20ICAP%20Server%7C_____0" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ThreatPrevention_AdminGuide/Topics-TPG/ICAP_Server.htm?tocpath=ICAP%7CThe%20Security%20Gateway%20as%20an%20ICAP%20Server%7C_____0&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 02:26:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164912#M27506</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-13T02:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to Integrate Firewalls and SSL Decryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164922#M27507</link>
      <description>&lt;P&gt;You can, yes, but it has some limitations in this mode.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk123412&amp;amp;partition=Basic&amp;amp;product=Threat" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk123412&amp;amp;partition=Basic&amp;amp;product=Threat&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 03:10:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/164922#M27507</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-13T03:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to Integrate Firewalls and SSL Decryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/165100#M27523</link>
      <description>&lt;P&gt;If you are using F5 for load balancing, offload the TSL termination to the F5. I have several TLS-heavy customers that do this. I also see more and more dumping F5/Bluecoat/etc. as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;said, it's becoming too expensive, vs. moving up a gateway model.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 22:00:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/165100#M27523</guid>
      <dc:creator>Jim_Holmes</dc:creator>
      <dc:date>2022-12-13T22:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to Integrate Firewalls and SSL Decryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/165345#M27576</link>
      <description>&lt;P&gt;I am trying to integrate with ICAP in my current configuration.&lt;BR /&gt;I think interworking with ICAP is a better way than processing the same traffic twice. Do you agree with me?&lt;/P&gt;&lt;P&gt;Are there many references to enabling and using ICAP on a firewall?&lt;/P&gt;&lt;P&gt;And what are the considerations when activating ICAP?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 02:38:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/165345#M27576</guid>
      <dc:creator>ykpark</dc:creator>
      <dc:date>2022-12-16T02:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to Integrate Firewalls and SSL Decryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/165347#M27577</link>
      <description>&lt;P&gt;The relevant ICAP reference material is already linked above.&lt;/P&gt;
&lt;P&gt;I'm otherwise not familiar enough with the capabilities of the F5 to advise.&lt;/P&gt;
&lt;P&gt;But as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&amp;nbsp;explained we would commonly expect the Firewall to be the meat in the sandwich between an ingress and egress F5 performing encrypt/decrypt functions, if this can be performed logically on the one appliance such that the Firewall doesn't see what it thinks is the same traffic twice then great.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 02:58:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-Integrate-Firewalls-and-SSL-Decryption/m-p/165347#M27577</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-16T02:58:00Z</dc:date>
    </item>
  </channel>
</rss>

