<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint Client: Client Hello with SNI? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Client-Client-Hello-with-SNI/m-p/227720#M3139</link>
    <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;One of my customers are using a third party cloud proxy provider where they define exceptions based on the SNI not the IP address.&lt;/P&gt;&lt;P&gt;They've created the VPN site with the URL rather than the IP address. Now they've now noticed that the Check Point Endpoint client not always sends the SNI but sometimes uses the IP only in the Client Hello.&lt;/P&gt;&lt;P&gt;This results in the proxy client on the endpoint sending these packages to the cloud proxy rather than directly to the Check Point gateway and subsequently traffic being inspected or not forwarded to the gateway.&lt;/P&gt;&lt;P&gt;I haven't found a setting in trac_client_1.ttm to always include the SNI in the Client Hello, has anybody else come across the issue and solved it with any other method but defining the exceptions based on IP?&lt;/P&gt;&lt;P&gt;Is this even considered and/or supported from Check Point side?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Soenke&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TCPdump_Screenshot.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27758i15F89FB932349CB1/image-size/large?v=v2&amp;amp;px=999" role="button" title="TCPdump_Screenshot.png" alt="TCPdump_Screenshot.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2024 09:38:48 GMT</pubDate>
    <dc:creator>Soenke_Weiss1</dc:creator>
    <dc:date>2024-09-24T09:38:48Z</dc:date>
    <item>
      <title>Endpoint Client: Client Hello with SNI?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Client-Client-Hello-with-SNI/m-p/227720#M3139</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;One of my customers are using a third party cloud proxy provider where they define exceptions based on the SNI not the IP address.&lt;/P&gt;&lt;P&gt;They've created the VPN site with the URL rather than the IP address. Now they've now noticed that the Check Point Endpoint client not always sends the SNI but sometimes uses the IP only in the Client Hello.&lt;/P&gt;&lt;P&gt;This results in the proxy client on the endpoint sending these packages to the cloud proxy rather than directly to the Check Point gateway and subsequently traffic being inspected or not forwarded to the gateway.&lt;/P&gt;&lt;P&gt;I haven't found a setting in trac_client_1.ttm to always include the SNI in the Client Hello, has anybody else come across the issue and solved it with any other method but defining the exceptions based on IP?&lt;/P&gt;&lt;P&gt;Is this even considered and/or supported from Check Point side?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Soenke&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TCPdump_Screenshot.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27758i15F89FB932349CB1/image-size/large?v=v2&amp;amp;px=999" role="button" title="TCPdump_Screenshot.png" alt="TCPdump_Screenshot.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 09:38:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Client-Client-Hello-with-SNI/m-p/227720#M3139</guid>
      <dc:creator>Soenke_Weiss1</dc:creator>
      <dc:date>2024-09-24T09:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Client: Client Hello with SNI?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Client-Client-Hello-with-SNI/m-p/228009#M3140</link>
      <description>&lt;P&gt;I don't think there is such a setting anywhere in the client configuration. However, I would advise you to raise a TAC ticket and get an official answer to the matter.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 09:51:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Client-Client-Hello-with-SNI/m-p/228009#M3140</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-09-26T09:51:01Z</dc:date>
    </item>
  </channel>
</rss>

