<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP/2 over TLS in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67387#M2592</link>
    <description>&lt;P&gt;I do not think that&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116022" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;SK116022&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;was valid for 77.20.8x SMB appliances. Also, it suggests to either downgrade the traffic to http/1.1 for SSL Inspection or either drop or allow http/2 without SSL inspection. So it seems there currently is no&amp;nbsp;inspection of&amp;nbsp;HTTP/2 over TLS possible...&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2019 10:27:34 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-11-14T10:27:34Z</dc:date>
    <item>
      <title>HTTP/2 over TLS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67376#M2591</link>
      <description>&lt;P&gt;Regarding inspection of&amp;nbsp;&lt;SPAN&gt;HTTP/2 over TLS there is the&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116022" target="_blank" rel="noopener"&gt;SK116022&lt;/A&gt;&amp;nbsp;but what do you say? Is it valid for 77.20.87 ? Because I have HTTPS Inspection enabled and it does not look like it is inspecting that kind of traffic.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 07:00:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67376#M2591</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2019-11-14T07:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP/2 over TLS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67387#M2592</link>
      <description>&lt;P&gt;I do not think that&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116022" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;SK116022&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;was valid for 77.20.8x SMB appliances. Also, it suggests to either downgrade the traffic to http/1.1 for SSL Inspection or either drop or allow http/2 without SSL inspection. So it seems there currently is no&amp;nbsp;inspection of&amp;nbsp;HTTP/2 over TLS possible...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 10:27:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67387#M2592</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-11-14T10:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP/2 over TLS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67404#M2593</link>
      <description>&lt;P&gt;How do I "downgrade" HTTP/2 to HTTP/1.1 ?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 12:35:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67404#M2593</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2019-11-14T12:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP/2 over TLS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67454#M2596</link>
      <description>Enable HTTPS Inspection.&lt;BR /&gt;Otherwise you block it using App Control.&lt;BR /&gt;&lt;BR /&gt;Note that HTTP/2 support is planned for R80.40, not sure when it is planned for SMB.</description>
      <pubDate>Thu, 14 Nov 2019 17:40:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67454#M2596</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-14T17:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP/2 over TLS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67459#M2597</link>
      <description>&lt;P&gt;Hmm, I am a bit confused here. I have HTTPS Inspection enabled and it still logs application name as "HTTP/2 over TLS". Isn't it supposed to recognize the actual app encapsulated inside it ?&lt;/P&gt;
&lt;P&gt;Also, what will happen (from user point of view) if I block it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 18:12:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67459#M2597</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2019-11-14T18:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP/2 over TLS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67464#M2598</link>
      <description>Are you sure you are HTTPS Inspecting the traffic in question?&lt;BR /&gt;We don't yet parse inside HTTP/2 over TLS yet.&lt;BR /&gt;The browser should be smart enough to realize HTTP/2 over TLS isn't supported and downgrade to HTTP/1.1 if you block it.&lt;BR /&gt;</description>
      <pubDate>Thu, 14 Nov 2019 19:19:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67464#M2598</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-14T19:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP/2 over TLS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67488#M2601</link>
      <description>&lt;P&gt;Yes, I am sure HTTPS Inspection is in use. But you are most certainly right. It is decrypting but not parsing it inside. I will block it and see what happens. Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 03:34:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67488#M2601</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2019-11-15T03:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP/2 over TLS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67491#M2603</link>
      <description>&lt;P&gt;No, Blocking does just that. Blocks it. For the connection to be downgraded to HTTP/1.1, SMB must tell the browser HTTP/2 is not supported for this connection. And it is not doing that. So, that's not an option really. Too bad because HTTP/2 connections are becoming more and more common.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 05:04:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/67491#M2603</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2019-11-15T05:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP/2 over TLS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/128999#M5703</link>
      <description>&lt;P&gt;Hi! Want to revive this old topic &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; We are running R80.40 T120 and most HTTP/2 logs show no actual resource. HTTPS interception is enabled as per my screenshot. Anyone has had better answers than sk116022?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13644i61B81EB0BC879697/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2021 07:15:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HTTP-2-over-TLS/m-p/128999#M5703</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-09-09T07:15:05Z</dc:date>
    </item>
  </channel>
</rss>

