- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Does somebody know what the difference between these 2 options is:
HTTPS Inspection Advanced Settings - Bypass Allow List - Well-known Update Services:
Updatable Objects - HTTPS services - recommended bypass:
Is it recommended to use both the setting and the Updatable Object? Are they equivalent to each other? sk98655 shows the same list of update services as in the Updatable Object, apart from VMware updates. So is that the only difference?
We're on R82, both MGMT and gateways.
It has been a long time since I used HTTPS inspection intensively, but in my youthful recklessness, I would argue that the former applies globally and the latter can be applied granularly in policies.
Just did some more lab checks and I see one that you mentioned for https bypass, seems more related to windows updates.
It has been a long time since I used HTTPS inspection intensively, but in my youthful recklessness, I would argue that the former applies globally and the latter can be applied granularly in policies.
Ah, that makes sense. Thank you!
This is what sk shows, more less what you posted. I use inspection in the lab, so happy to test whatever you need.
Just did some more lab checks and I see one that you mentioned for https bypass, seems more related to windows updates.
Hi Andy,
Thanks for testing. We're having a few small problems with updates and downloads from the MS Store after enabling HTTPS Inspection. We are not using the Updatable Object currently, so I'll try that next week, maybe it'll fix these problems 😀
Sounds good, keep us posted!
Just wanted to update the thread. We tried the Updatable object, but it still didn't bypass the MS store traffic so we created a custom application with the MS domains seen in the log during the failed MS store update and that worked for us. So I guess, there's no difference content-wise between the Bypass Allow List in the Global Settings and the Updatable Object, just the possibility to set it granularly via the Updatable Object instead of being applied globally, as @Vincent_Bacher said.
Thanks for the update. Yes, that makes sense.
@StephS I did some lab tests today, since I have windows 11 PC behind R81.20 cluster with https inspection on. I disabled that option to bypass traffic to update services and after installing policy, windows update failed. Did not try mozilla one, but Im sure that would have failed too.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 33 | |
| 11 | |
| 10 | |
| 10 | |
| 9 | |
| 7 | |
| 7 | |
| 7 | |
| 6 | |
| 6 |
Thu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY