<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS Inspection Harmony Connect Beta in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/113850#M194</link>
    <description>&lt;P&gt;One of the downsides of HTTPS inspection has been the perceived complexity with basically setting up what is a MITM configuration. Harmony does a pretty good job at presenting the setup of HTTPS inspection but doesn't quite go into enough detail. You have a nice selection box for enabling it versus Basic but when it comes time to implement it you just say, Download Certs or Upload your own. There is zero help and assumes a great deal of prior knowledge which a newcomer may not have. I think this is an area that can be improved.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Mar 2021 20:24:34 GMT</pubDate>
    <dc:creator>Tony_Graham</dc:creator>
    <dc:date>2021-03-17T20:24:34Z</dc:date>
    <item>
      <title>HTTPS Inspection Harmony Connect Beta</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/113850#M194</link>
      <description>&lt;P&gt;One of the downsides of HTTPS inspection has been the perceived complexity with basically setting up what is a MITM configuration. Harmony does a pretty good job at presenting the setup of HTTPS inspection but doesn't quite go into enough detail. You have a nice selection box for enabling it versus Basic but when it comes time to implement it you just say, Download Certs or Upload your own. There is zero help and assumes a great deal of prior knowledge which a newcomer may not have. I think this is an area that can be improved.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 20:24:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/113850#M194</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2021-03-17T20:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Harmony Connect Beta</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/113873#M206</link>
      <description>&lt;P&gt;Ultimately, what is required for HTTPS Inspection is a Certificate Authority key.&lt;BR /&gt;You can either generate that yourself (if you have an enterprise CA your users already trust) or use ours.&lt;BR /&gt;In either case, you will have to distribute this CA key to your users and ensure it is marked trusted.&lt;/P&gt;
&lt;P&gt;And, you're correct: this could be clearer.&lt;BR /&gt;Another one for&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/332"&gt;@Tomer_Sole&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 22:43:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/113873#M206</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-17T22:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Harmony Connect Beta</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/113878#M210</link>
      <description>&lt;P&gt;Thank you for this suggestion - indeed we should explain in more detail about the underlying technology. Our on-premises products have had detailed best practices for years, and even though we run the same software under the hood, the use cases are sharpened for mostly outbound traffic (inbound is coming later this year) and the web management is different than the on-premises management described at those guides. So until we spin-off the guides from our on-premises products, you are welcome to see this one:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108202" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108202&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also until we work out the guides, a few advices below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Harmony Connect has 3 deployment types:&lt;/P&gt;
&lt;P&gt;- Branch offices - where the administrator needs to deploy the certificate at the computers of the end users&lt;/P&gt;
&lt;P&gt;- Remote users - the default certificate is actually automatically deployed as part of the first-time activation of Harmony Connect App. In case the admin modifies the certificate, they then do need to deploy the replaced certificate at the computers of the end users&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Client-less users - this use case is not applicable and SSL Inspection happens the other way around. Users do not need a special certificate in this case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 23:44:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/113878#M210</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2021-03-17T23:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Harmony Connect Beta</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/113957#M212</link>
      <description>&lt;P&gt;Thank you for the clarifications. If you put one line in the 'Download Full Inspection Certificate', and/or the popup when you click&lt;/P&gt;&lt;P&gt;on 'Select' I think it would go a long way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "A default certificate is automatically deployed as part of the first-time activation of Harmony Connect App."&lt;/P&gt;&lt;P&gt;Otherwise if all someone is using it for are Remote Users they may try and deploy, install and update the end user certificates&lt;/P&gt;&lt;P&gt;which is both unnecessary and a waste of effort. If I am understanding you correctly.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 15:36:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/113957#M212</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2021-03-18T15:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Harmony Connect Beta</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/114006#M217</link>
      <description>&lt;P&gt;That is correct - thanks&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 18:29:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/HTTPS-Inspection-Harmony-Connect-Beta/m-p/114006#M217</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2021-03-18T18:29:25Z</dc:date>
    </item>
  </channel>
</rss>

