<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: https inspection drop in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-drop/m-p/188905#M31676</link>
    <description>&lt;P&gt;Why the question - either the connection is https inspected or excluded from that. Acceleration should not make any difference afaik. Here, a probe is sent to the site that fails for some reason - used cipher not supported,&amp;nbsp;SNI verification failed or else. I would do an exclusion for government websites as they should not contain malware and customer is connecting using special apps.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2023 10:22:07 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-08-08T10:22:07Z</dc:date>
    <item>
      <title>https inspection drop</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-drop/m-p/188898#M31672</link>
      <description>&lt;P&gt;We are having a problem connecting to government websites.&lt;BR /&gt;We have enabled https inspection exception for these sites.&lt;BR /&gt;Users use special software to connect to these sites.&lt;BR /&gt;The first log shows accept.&lt;BR /&gt;But there is a second log drops with the message "The probe sent to destination has encountered a general error ", "Dropping request as configured in engine settings of HTTPS Inspection".&lt;BR /&gt;Can you tell me what the problem might be?&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ddf73200-5c0d-4fba-a42c-2f60ba8bf5c2.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21998i05C0F0AD321EFF0C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ddf73200-5c0d-4fba-a42c-2f60ba8bf5c2.jpg" alt="ddf73200-5c0d-4fba-a42c-2f60ba8bf5c2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 09:49:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-inspection-drop/m-p/188898#M31672</guid>
      <dc:creator>Hllrdm</dc:creator>
      <dc:date>2023-08-08T09:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection drop</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-drop/m-p/188901#M31674</link>
      <description>&lt;P&gt;Look at the https settings:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="https.png" style="width: 637px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22000i6A703B1D79F59AEB/image-size/large?v=v2&amp;amp;px=999" role="button" title="https.png" alt="https.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If it is on fail-close, the drop is not unexpected...&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 10:00:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-inspection-drop/m-p/188901#M31674</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-08T10:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection drop</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-drop/m-p/188903#M31675</link>
      <description>&lt;P&gt;And if we use fast accel for this connection, in that case drops will also be there?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 10:10:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-inspection-drop/m-p/188903#M31675</guid>
      <dc:creator>Hllrdm</dc:creator>
      <dc:date>2023-08-08T10:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection drop</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-inspection-drop/m-p/188905#M31676</link>
      <description>&lt;P&gt;Why the question - either the connection is https inspected or excluded from that. Acceleration should not make any difference afaik. Here, a probe is sent to the site that fails for some reason - used cipher not supported,&amp;nbsp;SNI verification failed or else. I would do an exclusion for government websites as they should not contain malware and customer is connecting using special apps.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 10:22:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-inspection-drop/m-p/188905#M31676</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-08T10:22:07Z</dc:date>
    </item>
  </channel>
</rss>

