- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hi
Found the Checkpoint HTTPS INSPECTION cert is SHA1 and as it is outdated should move forward to SHA256. Followed the sk115894 but when accessing, the browser is not trusting the certificate. Kindly help on resolving this issue.
Its R80.30 with Take 76.
Can you please brief to replace the existing certificate SHA1 and its in production now.
Wandering if Stage 6 has been done which requires to install the new SHA-256 Cert into the Trusted Root CA Folder on the Windows machines.
If reading write then have updated the Cert but the Machines not trusting the Certificates from the New Certificate which points to the new Cert not being Trusted.
The certificate .crt is already added in the Trusted Root Certificate.
If the new SHA-256 Cert is in the Trusted CA Root Folder then you will need to investigate on the Client Machines why they are not trusting the new Root CA even though added as a Trusted CA Root Certificate.
Created a different lab and tested and am getting the same error message. I think some configuration of installing the certificate is missing in the Dashboard.
You are going to have to list out exactly step by step what done then as the SK seems to contain what to do when reading through,
Shows a little more about having once opened an R80.x SmartDashboard for the HTTPS Inspection Policy but is once in there the same as on R77.x in the SK,
I would think that Check Point take it that you need to install the Policy afterwards for it to take affect as a given as is hammered into everyone that make a change and need to install Policy afterwards.
If haven't finished importing the SHA-256 Cert then would still be using the SHA-1 which presumbably you had working fine so wouldn't get any errors still.
So How have you exported the certificate and then distributed the Client Machines as if the Client PC not trusting the Certs then it looks as though either not in the Trusted Root CA store on the machine or hasn't imported to the machine properly for which looking more at the PC rather then Check Point.
After enabling PBR, HTTPS INSPECTION is not working to the interface where PBR is enabled. Is there any limitation in HTTPS INSPECTION with PBR. Able to get the certificate and page takes too much time to load and much often doesn't load. External Interface without PBR works fine perfectly.
I could see traffic flowing through both External Interface when HTTPS INSPECTION is enabled.
The following features/blades are not supported with PBR:
HTTPS Inspection listed there. Cannot do HTTPS Inspection with PBR. Pretty much all you can run on a Check Point with PBR enabled is the Firewall Blade.
Thank You so much for your reply.
I have seen this SK before but some of our customers are using HTTPS INSPECTION with PBR successfully in the same version.
Even IPS and URLF was working fine over there. I could see PBR traffic with IPS Events in logs.
We had created a test Lab and tested, and the test was a success.
What i had noticed in production environment is "PBR NAT IP is again coming as a source in next External interface with the same destination IP".
Is there anyway we can avoid the above situation mentioned in double quotes.
Hi,
Can you please conform sk100500 is relevant or not, as PBR works with HTTPS INPECTION for some environment and creating issues on others. Is the SK relevant.
Yes the SK article is VERY relevant as quite clearly says is NOT SUPPORTED. That is not to be confused with DOES NOT WORK.
So you are running in an unsupported configuration when running HTTPS Inspection and configuring PBR.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 6 | |
| 6 | |
| 6 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY