Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Alex-
MVP Silver
MVP Silver

Chaining of HTTPS Inspection gateways for different blades

SMS is R82.10.

Central site: R82

Remote sites: R81.20, being upgraded to R82.10.

 

Customer has remote sites using gateways with NGTP license, then connect and breakout to a central site with NGTX license.

They want to activate HTTPS Inspection. The question is do it on the central site, which will then have to handle all the sites, or do it for supported blades locally and for the NGTX-only blades centrally to distribute the workload.

 

Remote Site : HTTPS Inspect for blades IPS/APPI/URLF/AV/AB ----> Central site: HTTPS Inspect for TE/ZP --> Internet

Is this supposed to work with this design? For instance, let's say an attchment is downloaded and goes AV (local) / TE (central) - will the central FW see the client as source or the local FW who already inserted itself in the HTTPS stream?

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

To the central gateway, the connection will appear to come from the original client.
You will need to add the Central Site's outgoing HTTPS Inspection CA to the Remote Site if you're going to chain in this manner.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events