<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: website is not dispalyed in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113285#M447</link>
    <description>&lt;P&gt;You have a kinda old setup R80.20SP&amp;nbsp;&lt;SPAN&gt;Take 191 (2 Dec 2019, GA from 05 Jan 2020), strongly advice to upgrade it. The website is only allowing TLS 1.2 and only one strong cipher suite&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, old GW TLS engine and old ciphers are your problem.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Mar 2021 08:57:17 GMT</pubDate>
    <dc:creator>Martin_Raska</dc:creator>
    <dc:date>2021-03-12T08:57:17Z</dc:date>
    <item>
      <title>website is not dispalyed</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113170#M443</link>
      <description>&lt;P&gt;Hi team - for some reason this website is not dispalyed. outside the gateway is working fine.&lt;/P&gt;&lt;P&gt;TLSv1 is disabled, but for some reason the gateway is still using TLSv1 to connect on behalve the user.&lt;/P&gt;&lt;P&gt;We made a https bypass, but no succes &amp;nbsp;&lt;/P&gt;&lt;P&gt;The exact message displyaed is:&lt;/P&gt;&lt;P&gt;This page canâ€™t be displayed&lt;/P&gt;&lt;P&gt;Turn on TLS 1.0, TLS 1.1, and TLS 1.2 in Advanced settings and try connecting to &lt;STRONG&gt;&lt;A href="https://lft.ema.kpmg.com" target="_blank"&gt;https://lft.ema.kpmg.com&lt;/A&gt; &lt;/STRONG&gt;again. If this error persists, it is possible that this site uses an unsupported protocol or cipher suite such as RC4 &lt;A href="http://go.microsoft.com/fwlink/?LinkId=735074" target="_blank"&gt;(link for the details)&lt;/A&gt;, which is not considered secure. Please contact your site administrator.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you have any suggestion for this? thank you&lt;/P&gt;&lt;P&gt;Khalid&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 13:50:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113170#M443</guid>
      <dc:creator>Khalid</dc:creator>
      <dc:date>2021-03-11T13:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: website is not dispalyed</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113239#M444</link>
      <description>&lt;P&gt;What version/JHF level is the gateway?&lt;BR /&gt;Is HTTPS Inspection enabled?&lt;BR /&gt;What do you see in the gateway logs when you try and access the site?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 21:02:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113239#M444</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-11T21:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: website is not dispalyed</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113275#M445</link>
      <description>&lt;P&gt;Hi PhoneBoy, Tank you for reply&lt;/P&gt;&lt;P&gt;What version/JHF level is the gateway? &amp;gt;&amp;gt; R80.20SP/T191&lt;BR /&gt;Is HTTPS Inspection enabled? &amp;gt;&amp;gt;Yes enabled&lt;BR /&gt;What do you see in the gateway logs when you try and access the site?&amp;gt;&amp;gt; the traffic is allowed&amp;nbsp;&lt;/P&gt;&lt;P&gt;We observed in the TCPDUMP that the gateway is sending TLSv1 but the website is using TLSv1.2. possible the cause of the issue but not sure.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 06:45:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113275#M445</guid>
      <dc:creator>Khalid</dc:creator>
      <dc:date>2021-03-12T06:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: website is not dispalyed</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113276#M446</link>
      <description>&lt;P&gt;You may debug that as per&amp;nbsp;&lt;SPAN&gt;sk105559&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 07:03:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113276#M446</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2021-03-12T07:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: website is not dispalyed</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113285#M447</link>
      <description>&lt;P&gt;You have a kinda old setup R80.20SP&amp;nbsp;&lt;SPAN&gt;Take 191 (2 Dec 2019, GA from 05 Jan 2020), strongly advice to upgrade it. The website is only allowing TLS 1.2 and only one strong cipher suite&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, old GW TLS engine and old ciphers are your problem.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 08:57:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/website-is-not-dispalyed/m-p/113285#M447</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2021-03-12T08:57:17Z</dc:date>
    </item>
  </channel>
</rss>

