<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proxy and SecureXL in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Proxy-and-SecureXL/m-p/17731#M3025</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are running R77.30 for this customer.&lt;/P&gt;&lt;P&gt;In Proxy environment you do not need to enable the HTTPS inspection separately as the traffic is unpacked anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in this case we really need to have this traffic in bypass-the-proxy-mode to move it into the PXL path. So we have asked the customer to adjust the proxy pac file, so we can add a small policy to allow this traffic to pass and be moved to PXL path.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Dec 2018 08:54:30 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2018-12-20T08:54:30Z</dc:date>
    <item>
      <title>Proxy and SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-and-SecureXL/m-p/17729#M3023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any way that SecureXL Medium path can be used when the GW is used as a proxy?&lt;/P&gt;&lt;P&gt;We have a customer that has a 15600 and they have asked us to setup a proxy for several reasons. Now they are migrating to Office365 and I see a lot of traffic hitting the FW path, some traffic hitting the medium path and none hitting the fast path.&lt;/P&gt;&lt;P&gt;As Proxy traffic needs to be handled by the gateway itself, I would not expect this to be able to accelerated, so my thoughts were to ask the customer to exclude the Office 365 URL's from the PAC file, so they will not use the proxy, thus allowing this traffic to be accelerated.&lt;/P&gt;&lt;P&gt;They also have WiFi networks that do not need to use the proxy and we see 200/600Mbps in traffic in PXL/FW paths.&amp;nbsp;We have&amp;nbsp;12 cores for the FW-Workers but are all at or close to 100% at the busy moments.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 14:50:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-and-SecureXL/m-p/17729#M3023</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-12-19T14:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy and SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-and-SecureXL/m-p/17730#M3024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In R80.10 gateway and earlier I'm pretty sure the answer is no.&amp;nbsp; This might be handled differently in R80.20 gateway however due to the wholesale changes in SecureXL, but I doubt it.&amp;nbsp; See:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92482" target="_blank"&gt;sk92482 - Performance impact from enabling HTTP/HTTPS Proxy functionality&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you are inspecting Office 365 traffic, you probably have HTTPS Inspection enabled which will force F2F handling for all traffic subject to it anyway on R80.10 gateway regardless of whether proxy mode is used or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 15:47:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-and-SecureXL/m-p/17730#M3024</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-12-19T15:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy and SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-and-SecureXL/m-p/17731#M3025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are running R77.30 for this customer.&lt;/P&gt;&lt;P&gt;In Proxy environment you do not need to enable the HTTPS inspection separately as the traffic is unpacked anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in this case we really need to have this traffic in bypass-the-proxy-mode to move it into the PXL path. So we have asked the customer to adjust the proxy pac file, so we can add a small policy to allow this traffic to pass and be moved to PXL path.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 08:54:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-and-SecureXL/m-p/17731#M3025</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-12-20T08:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy and SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-and-SecureXL/m-p/17732#M3026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct, the answer is NO&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 10:47:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-and-SecureXL/m-p/17732#M3026</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-12-20T10:47:56Z</dc:date>
    </item>
  </channel>
</rss>

