<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS inspection utilization impact in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223654#M37276</link>
    <description>&lt;P&gt;Yep, agree, ssl inspection is best in R81.20, no doubt about it. So far, R82 EA seems okay, but lets wait till its GA.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 14 Aug 2024 13:41:39 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-08-14T13:41:39Z</dc:date>
    <item>
      <title>HTTPS inspection utilization impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223264#M37182</link>
      <description>&lt;P&gt;I want to enable HTTPS inspection to enable DPI in the maestro environment. Before that, I need to clear some queries.&lt;/P&gt;&lt;P&gt;1. If HTTPS inspection is enabled then what is the impact on CPU+Memory utilization?&lt;BR /&gt;2. Is it possible to install various types of certificates like wildcard, SSL, and so on for various services?&lt;BR /&gt;3. If I enable the HTTPS inspection blade, does it automatically inspect both inbound and outbound traffic? If yes, then is there any option to separate?&lt;/P&gt;&lt;P&gt;Please provide the official document/SK regarding these queries. Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 11 Aug 2024 11:37:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223264#M37182</guid>
      <dc:creator>maxtaan</dc:creator>
      <dc:date>2024-08-11T11:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection utilization impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223266#M37183</link>
      <description>&lt;P&gt;We now publish HTTPS numbers on the datasheets for 9000 / 19200 / 29200 appliances.&lt;/P&gt;
&lt;P&gt;Inbound vs outbound is controlled separately, please refer to the documentation:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/HTTPS-Inspection.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/HTTPS-Inspection.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk65123" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk65123&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108202" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108202&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Aug 2024 12:04:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223266#M37183</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-11T12:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection utilization impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223272#M37189</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk65123" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk65123&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="checkpoint_toggle" target="_blank"&gt;Is there a performance impact when enabling HTTPS Inspection on the gateway?&lt;/A&gt;&lt;/P&gt;
&lt;DIV id="Q9"&gt;
&lt;BLOCKQUOTE&gt;HTTPS Inspection requires the Security Gateway to perform extra SSL work:
&lt;UL&gt;
&lt;LI&gt;SSL handshake with the secure web site and with the client browser.&lt;/LI&gt;
&lt;LI&gt;Decrypt &amp;amp; re-encrypt all SSL traffic, to be able to inspect it.&lt;/LI&gt;
&lt;/UL&gt;
&lt;BR /&gt;This has some performance impact on SSL capacity and latency, but in normal situations the end user should not be aware of it.
&lt;P class="1723402720486"&gt;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108202" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108202&lt;/A&gt;&lt;/P&gt;
&lt;H3 id="Performance"&gt;(Part 4) Performance&lt;/H3&gt;
&lt;DIV&gt;&lt;A class="checkpoint_toggle" target="_blank"&gt;Show / Hide this section&lt;/A&gt;&lt;BR /&gt;
&lt;DIV id="Toggle_Part_4"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;HTTPS Inspection creates additional load on Security Gateway's CPU and increased RAM usage due to these reasons:&lt;/P&gt;
&lt;P&gt;TLS termination, encrypt/decrypt and active TCP termination.&lt;/P&gt;
&lt;P&gt;Additional traffic is inspected by security blades.&lt;/P&gt;
&lt;P&gt;In general, the more blades and security features, the higher the additional load.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 11 Aug 2024 19:06:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223272#M37189</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-11T19:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection utilization impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223281#M37197</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp; , You have answered only one question from the three that I raised. Can you please answer the rest two the way you answered the first one?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 05:57:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223281#M37197</guid>
      <dc:creator>maxtaan</dc:creator>
      <dc:date>2024-08-12T05:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection utilization impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223366#M37205</link>
      <description>&lt;P&gt;The rest you can find in the links that Chris posted above&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 17:05:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223366#M37205</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-12T17:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection utilization impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223369#M37206</link>
      <description>&lt;P&gt;&lt;SPAN&gt;1. If HTTPS inspection is enabled then what is the impact on CPU+Memory utilization?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;For powerful firewalls, you wont see much impact at all.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Is it possible to install various types of certificates like wildcard, SSL, and so on for various services?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Yes, they are, see point 23&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk65123" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk65123&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;3. If I enable the HTTPS inspection blade, does it automatically inspect both inbound and outbound traffic? If yes, then is there any option to separate?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No it does NOT, they are totally separate and inbound inspection needs its own cert (.p12 format) imported.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 17:47:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223369#M37206</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-12T17:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection utilization impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223404#M37216</link>
      <description>&lt;P&gt;Outbound inspection requires a CA certificate trusted by your clients to be used.&lt;BR /&gt;(Which means it cannot be used for people outside your organization)&lt;/P&gt;
&lt;P&gt;For inbound inspection, you use the same certificate as your server.&lt;BR /&gt;If you're protecting multiple sites using the same public IP, you will need to use a single certificate that covers all the relevant FDQNs.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 22:22:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223404#M37216</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-12T22:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection utilization impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223415#M37219</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/88297"&gt;@maxtaan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To add to what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;said, you can also refer to my post below, hope it helps.&lt;/P&gt;
&lt;P&gt;Best and if you need help, happy to help you in the lab with it, as I have fully working R81.20 and R82 ssl inspection lab.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-tip/m-p/219139" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-tip/m-p/219139&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 22:53:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223415#M37219</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-12T22:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection utilization impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223653#M37275</link>
      <description>&lt;P&gt;Regarding point 1 this is subjective and version relevant, less of&amp;nbsp; an issue as of R81.20 but not insignificant by any means.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 13:40:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223653#M37275</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-14T13:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection utilization impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223654#M37276</link>
      <description>&lt;P&gt;Yep, agree, ssl inspection is best in R81.20, no doubt about it. So far, R82 EA seems okay, but lets wait till its GA.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 13:41:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-utilization-impact/m-p/223654#M37276</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-14T13:41:39Z</dc:date>
    </item>
  </channel>
</rss>

