<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro HTTPS Inspection in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168824#M1383</link>
    <description>&lt;P&gt;Did you check:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178625&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178625&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 00:28:05 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-01-24T00:28:05Z</dc:date>
    <item>
      <title>Maestro HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168696#M1381</link>
      <description>&lt;P&gt;We have a single gateway acting as a perimeter firewall and a maestro setup with 1 security group. Both are being managed by a Single SMS. Our testing aims to access Facebook but block Facebook-Posting. This requires HTTPS inspection and we enabled it&amp;nbsp;on both gateway and maestro.&lt;/P&gt;&lt;P&gt;Behind the gateway we have a test PC and it is working properly. Facebook posting is blocked, However, on the test PC behind Maestro, it's not working. Please see attached images for reference.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone experienced this before? Thanks in advance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 08:04:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168696#M1381</guid>
      <dc:creator>jnra</dc:creator>
      <dc:date>2023-01-23T08:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168743#M1382</link>
      <description>&lt;P&gt;Maestro logs say Unreached OSCP, which for me means the certificate is not recognized which means GW behind Maestro doesn't decrypt the traffic. Dig in this direction.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 14:22:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168743#M1382</guid>
      <dc:creator>MartinTzvetanov</dc:creator>
      <dc:date>2023-01-23T14:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168824#M1383</link>
      <description>&lt;P&gt;Did you check:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178625&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178625&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 00:28:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168824#M1383</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-24T00:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168826#M1384</link>
      <description>&lt;P&gt;Yes. I tried getting the current value with fw ctl get command but I'm getting an error. Will update you once I get to work on our setup later.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 01:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168826#M1384</guid>
      <dc:creator>jnra</dc:creator>
      <dc:date>2023-01-24T01:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168827#M1385</link>
      <description>&lt;P&gt;I performed sk&lt;SPAN&gt;178625 and change the value of appi_urlf_ssl_cn_perform_hold_for_cert_validation from 0 to 1 but still I encountered the same issue. I still get lots of "Unreached OCSP" https validation.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have opened a TAC case for this concern as well.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 01:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168827#M1385</guid>
      <dc:creator>jnra</dc:creator>
      <dc:date>2023-01-24T01:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168926#M1389</link>
      <description>&lt;P&gt;Do you have Layer 4 distribution enabled?&amp;nbsp; It is by default...&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 12:48:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/168926#M1389</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-01-24T12:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/169000#M1393</link>
      <description>&lt;P&gt;Yes. L4 mode was enabled. I also tried setting the interfaces distribution mode manually by setting external interface as network and internal interface as user.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 01:06:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/169000#M1393</guid>
      <dc:creator>jnra</dc:creator>
      <dc:date>2023-01-25T01:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/169002#M1394</link>
      <description>&lt;P&gt;Is the connection being HTTPS Inspected on both the Maestro SG and the perimeter gateway? Double inspection is not supported, so either just do it on the perimeter gateway or make sure that you exclude the Maestro IPs and the networks behind the Maestro from inspection on the perimeter gateway,&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 01:56:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/169002#M1394</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2023-01-25T01:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/169003#M1395</link>
      <description>&lt;P&gt;On my initial setup, Maestro SG is behind perimeter firewall. Currently, I have&amp;nbsp; a direct internet connection for Maestro SG.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 02:03:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/169003#M1395</guid>
      <dc:creator>jnra</dc:creator>
      <dc:date>2023-01-25T02:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro HTTPS Inspection</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/169011#M1396</link>
      <description>&lt;P&gt;Thank you everyone. the issue was resolved after blocking Quic and Quic Protocol.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 03:01:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-HTTPS-Inspection/m-p/169011#M1396</guid>
      <dc:creator>jnra</dc:creator>
      <dc:date>2023-01-25T03:01:49Z</dc:date>
    </item>
  </channel>
</rss>

