<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unreached OCSP - causes serious lag in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245456#M3271</link>
    <description>&lt;P&gt;Never seen that sk before, GREAT reference&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64803"&gt;@AaronCP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Apr 2025 10:38:35 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-04-02T10:38:35Z</dc:date>
    <item>
      <title>Unreached OCSP - causes serious lag</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245412#M3264</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Setup&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Current setup is a Maestro R81 Take12. (already the case on Take10)&lt;/P&gt;&lt;P&gt;MHO140 /9300&amp;amp;9400's.&lt;/P&gt;&lt;P&gt;These is a serious delay in browsing websites thru the SG's.&lt;/P&gt;&lt;P&gt;Nearly all Security features are on - Sandblast suite.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Symthom&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;When browsing to a domain, the initial delay is 12-15sec, before it starts loading.&lt;/P&gt;&lt;P&gt;Seen these kinds of messages before in R81.20, but to compare :&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;R81.20 - 25msg in 1,5h, 500+ endpoints active 24/7&lt;/LI&gt;&lt;LI&gt;R82 - 25msg in 1,5&lt;STRONG&gt;min &lt;/STRONG&gt;5active users.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;So far&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;TAC is already involved, but wondering if somebody else is experiencing this issue?&lt;BR /&gt;Currently no big clue where the issue may reside.&lt;/P&gt;&lt;P&gt;The OCSP error very present, and near the timeline of the actions taken.&lt;BR /&gt;Certificate used in HTTPS Inspect is exactly the same as the existing setup.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's, apart of a RemoteAccess configuration move, the last hurdle I need to fix before being able to go live.&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 20:30:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245412#M3264</guid>
      <dc:creator>TimV</dc:creator>
      <dc:date>2025-04-01T20:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unreached OCSP - causes serious lag</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245427#M3265</link>
      <description>&lt;P&gt;OSCP is occurring because we are validating the certificate for the remote site is valid as part of SNI verification we do.&lt;BR /&gt;This occurs on anything where SNI is processed (App Control, URL Filtering, and HTTPS Inspection among others).&lt;BR /&gt;If the OSCP connection is failing somehow (you didn't include the message, but I assume that's what they are), that would account for the slowness of establishing the initial connection.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 23:58:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245427#M3265</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-01T23:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unreached OCSP - causes serious lag</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245428#M3266</link>
      <description>&lt;P&gt;OSCP would definitely have to do with certificate. Where is the error? Does it happen on client side or somewhere else?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 00:09:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245428#M3266</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-02T00:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unreached OCSP - causes serious lag</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245435#M3267</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/43552"&gt;@TimV&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Is there a way you can switch to CRL for certificate validation and see if it improves your situation?&lt;/P&gt;
&lt;P&gt;We had a scenario some time ago with validating VPN authentication certificates. From memory, there was a change in behaviour that defaulted to using OCSP, but when we switched back to CRL validation, it resolved our issue.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Aaron.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 06:30:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245435#M3267</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2025-04-02T06:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unreached OCSP - causes serious lag</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245436#M3268</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;How you would you do this?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 06:35:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245436#M3268</guid>
      <dc:creator>TimV</dc:creator>
      <dc:date>2025-04-02T06:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unreached OCSP - causes serious lag</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245437#M3269</link>
      <description>&lt;DIV class=""&gt;Hello&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Sorry about the missing information.&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;There are 2 types -&amp;nbsp;&lt;BR /&gt;One related to HTTPS Inspect, other one related to URLF.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Anyone a good guide on how to create a HTTPS inspect certificate with CRL and/or OCSP? ADCS based pref.&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Kind Regards&lt;/DIV&gt;&lt;DIV class=""&gt;Tim&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 06:39:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245437#M3269</guid>
      <dc:creator>TimV</dc:creator>
      <dc:date>2025-04-02T06:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unreached OCSP - causes serious lag</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245444#M3270</link>
      <description>&lt;P&gt;To resolve our issue, we used Scenario 2 in SK179434.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 08:21:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245444#M3270</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2025-04-02T08:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unreached OCSP - causes serious lag</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245456#M3271</link>
      <description>&lt;P&gt;Never seen that sk before, GREAT reference&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64803"&gt;@AaronCP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 10:38:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245456#M3271</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-02T10:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unreached OCSP - causes serious lag</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245475#M3272</link>
      <description>&lt;P&gt;Both issues have the same root cause, as explained earlier.&lt;BR /&gt;The Certificate used for HTTPS Inspection must be a Certificate Authority (i.e. can't be a wildcard cert).&lt;BR /&gt;The CRL/OSCP server used by the CA needs to be reachable by the gateway (also client in case of Remote Access).&lt;BR /&gt;Beyond that, no specific guidance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 13:45:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Unreached-OCSP-causes-serious-lag/m-p/245475#M3272</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-02T13:45:06Z</dc:date>
    </item>
  </channel>
</rss>

