<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ways to Disable TLS 1.0 &amp;amp; 1.1 on Outbound HTTPS Inspection traffic in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Ways-to-Disable-TLS-1-0-amp-1-1-on-Outbound-HTTPS-Inspection/m-p/283281#M47216</link>
    <description>&lt;P&gt;Hello Checkmates,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we were using HTTPS Inspection of Internet traffic quite successfully, without many issues, we recently started to do HTTPS Inspection on Inbound traffic towards one of our Web DMZ services.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the last 1.5 - 2 months, everything works quite well, but we bumped into some "false positives" while checking the SSL health/security from SSLLabs portal.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because the HTTPS traffic is terminated in Checkpoint, in order to be able to inspect it and do whatever else is necessary, it's accepting TLS1.0 &amp;amp; 1.1 even on our DMZ side we don't as we have minimum TLS 1.2 and 1.3 (max) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To address this, we found 3 ways only (recommended by TAC as well):&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Drop the connections at the kernel level, which can be configured through GuiDBEdit.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;This would affect not only the Inbound traffic – traffic from Internet to our DMZ that is HTTPS Inspected – but the Outbound traffic as well – traffic from internal clients to internet that is HTTPS Inspected. Therefore we can’t use this option.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Enable the relevant IPS protection. However, since Autonomous Prevention is being used, this option is not applicable in the current setup.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;We tried this, but because we are with Autonomous Threat Prevention, this is not possible as for the use of the IPS protections, we have to modify their actions and apply them into an IPS Policy. If we could do the changes to IPS protections and make use of those with the Autonomous Threat Prevention, it would be the best way to apply this.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Use an Access Control rule to block the traffic. This is the approach you have already implemented according to the Administration Guide. However, due to the Protocol Signature behavior described above, the first few packets may still be allowed before the connection is blocked.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;We tried this initially, and indeed the rule has hits, still it’s not acting for all traffic – we don’t understand why.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;If we use &lt;SPAN&gt;ssllabs.com&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to scan our DMZ portal, we see that even we don’t allow TLS 1.0 and TLS 1.1 on our DMZ portal, Checkpoint terminates the SSL connections and the TLS 1.0 and TLS 1.1 are working and the SSLLabs portal detecting that, grades the security of the site lower – due to the TLS 1.0 and TLS 1.1 being accepted by Checkpoint. We understand that the Protocol Signature few packets are being allowed, we don’t see that the access rule we have created is blocking.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%" height="601px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-10-07 091506.png" style="width: 883px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35457i93229EBFF541F4B5/image-dimensions/883x554?v=v2" width="883" height="554" role="button" title="Screenshot 2026-10-07 091506.png" alt="Screenshot 2026-10-07 091506.png" /&gt;&lt;/span&gt;
&lt;P&gt; &lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="100%" height="25px"&gt;
&lt;DIV id="tinyMceEditorSorin_Gogean_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-10-07 091610.png" style="width: 849px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35459iCE85B3C9F1430E5E/image-dimensions/849x624?v=v2" width="849" height="624" role="button" title="Screenshot 2026-10-07 091610.png" alt="Screenshot 2026-10-07 091610.png" /&gt;&lt;/span&gt;
&lt;P&gt; &lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So the question to you is, can I get this without impacting Inbound HTTPS traffic ?&amp;nbsp;&lt;BR /&gt;Is there something I missed in our settings/set-up?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;BR /&gt;PS: we have Checkpoint Maestro, with VSNext and Autonomous Threat Prevention on R82; and this weekend we'll have the latest JHF127 .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Oct 2026 06:47:29 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2026-10-07T06:47:29Z</dc:date>
    <item>
      <title>Ways to Disable TLS 1.0 &amp; 1.1 on Outbound HTTPS Inspection traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ways-to-Disable-TLS-1-0-amp-1-1-on-Outbound-HTTPS-Inspection/m-p/283281#M47216</link>
      <description>&lt;P&gt;Hello Checkmates,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we were using HTTPS Inspection of Internet traffic quite successfully, without many issues, we recently started to do HTTPS Inspection on Inbound traffic towards one of our Web DMZ services.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the last 1.5 - 2 months, everything works quite well, but we bumped into some "false positives" while checking the SSL health/security from SSLLabs portal.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because the HTTPS traffic is terminated in Checkpoint, in order to be able to inspect it and do whatever else is necessary, it's accepting TLS1.0 &amp;amp; 1.1 even on our DMZ side we don't as we have minimum TLS 1.2 and 1.3 (max) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To address this, we found 3 ways only (recommended by TAC as well):&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Drop the connections at the kernel level, which can be configured through GuiDBEdit.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;This would affect not only the Inbound traffic – traffic from Internet to our DMZ that is HTTPS Inspected – but the Outbound traffic as well – traffic from internal clients to internet that is HTTPS Inspected. Therefore we can’t use this option.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Enable the relevant IPS protection. However, since Autonomous Prevention is being used, this option is not applicable in the current setup.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;We tried this, but because we are with Autonomous Threat Prevention, this is not possible as for the use of the IPS protections, we have to modify their actions and apply them into an IPS Policy. If we could do the changes to IPS protections and make use of those with the Autonomous Threat Prevention, it would be the best way to apply this.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Use an Access Control rule to block the traffic. This is the approach you have already implemented according to the Administration Guide. However, due to the Protocol Signature behavior described above, the first few packets may still be allowed before the connection is blocked.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;We tried this initially, and indeed the rule has hits, still it’s not acting for all traffic – we don’t understand why.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;If we use &lt;SPAN&gt;ssllabs.com&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to scan our DMZ portal, we see that even we don’t allow TLS 1.0 and TLS 1.1 on our DMZ portal, Checkpoint terminates the SSL connections and the TLS 1.0 and TLS 1.1 are working and the SSLLabs portal detecting that, grades the security of the site lower – due to the TLS 1.0 and TLS 1.1 being accepted by Checkpoint. We understand that the Protocol Signature few packets are being allowed, we don’t see that the access rule we have created is blocking.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%" height="601px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-10-07 091506.png" style="width: 883px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35457i93229EBFF541F4B5/image-dimensions/883x554?v=v2" width="883" height="554" role="button" title="Screenshot 2026-10-07 091506.png" alt="Screenshot 2026-10-07 091506.png" /&gt;&lt;/span&gt;
&lt;P&gt; &lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="100%" height="25px"&gt;
&lt;DIV id="tinyMceEditorSorin_Gogean_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-10-07 091610.png" style="width: 849px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35459iCE85B3C9F1430E5E/image-dimensions/849x624?v=v2" width="849" height="624" role="button" title="Screenshot 2026-10-07 091610.png" alt="Screenshot 2026-10-07 091610.png" /&gt;&lt;/span&gt;
&lt;P&gt; &lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So the question to you is, can I get this without impacting Inbound HTTPS traffic ?&amp;nbsp;&lt;BR /&gt;Is there something I missed in our settings/set-up?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;BR /&gt;PS: we have Checkpoint Maestro, with VSNext and Autonomous Threat Prevention on R82; and this weekend we'll have the latest JHF127 .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2026 06:47:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ways-to-Disable-TLS-1-0-amp-1-1-on-Outbound-HTTPS-Inspection/m-p/283281#M47216</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2026-10-07T06:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Ways to Disable TLS 1.0 &amp; 1.1 on Outbound HTTPS Inspection traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ways-to-Disable-TLS-1-0-amp-1-1-on-Outbound-HTTPS-Inspection/m-p/283369#M47231</link>
      <description>&lt;P&gt;Have you tried:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk154532" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk154532&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2026 22:49:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ways-to-Disable-TLS-1-0-amp-1-1-on-Outbound-HTTPS-Inspection/m-p/283369#M47231</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-10-07T22:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Ways to Disable TLS 1.0 &amp; 1.1 on Outbound HTTPS Inspection traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ways-to-Disable-TLS-1-0-amp-1-1-on-Outbound-HTTPS-Inspection/m-p/283378#M47233</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;That we already have it set with TLS1.2 and it does not influence HTTPS Inspection of Inbound traffic.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you and have a nice week,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2026 06:29:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ways-to-Disable-TLS-1-0-amp-1-1-on-Outbound-HTTPS-Inspection/m-p/283378#M47233</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2026-10-08T06:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Ways to Disable TLS 1.0 &amp; 1.1 on Outbound HTTPS Inspection traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ways-to-Disable-TLS-1-0-amp-1-1-on-Outbound-HTTPS-Inspection/m-p/283403#M47236</link>
      <description>&lt;P&gt;Hi Sorin,&lt;/P&gt;
&lt;P&gt;The documentation is vague and and one might say even say incomplete for inbound inspection, we've had to resort to GuiDBedit to manipulate the minimum versions the gateways will accept.&lt;/P&gt;
&lt;P&gt;My observations:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;The gateways obeys the&amp;nbsp;ssl_min_ver parameter. You can raise the min_ver to 1.1 or 1.2 and it will be reflected after you push policy&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Conversely, ssl_max_ver is not obeyed. 1.2 is the highest setting but even so the gateway will still accept TLS 1.3&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;We were unable to manipulate the TLS levels successfully either with cipher_util. IPS or protocols in the access policy.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For your scenario you need to set the&amp;nbsp;ssl_min_ver parameter to whatever your minimum is&amp;nbsp; You do this like so:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;GuiDBEdit, on the tables tab, select Other - ssl_inspection&lt;/LI&gt;
&lt;LI&gt;In the Objects column, select geberal_confs_obj&lt;/LI&gt;
&lt;LI&gt;In the Fields columnm select the minimum and maximum TLS version values (min will be obeyed, max not)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Once done and policy pushed, give it a minute or two then your SSL Labs test should reflect the change.&lt;/P&gt;
&lt;P&gt;-Ruan&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2026 13:16:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ways-to-Disable-TLS-1-0-amp-1-1-on-Outbound-HTTPS-Inspection/m-p/283403#M47236</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2026-10-08T13:16:21Z</dc:date>
    </item>
  </channel>
</rss>

