- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi Checkmates!
We would like to enable HTTPS Inspection to have better security with URLF and App Control policy to tackle users query to inappropriate website and social media sites.
Due to mandatory install certificate on every devices, how about for mobile devices like android, ipad, etc? Is it mandatory to install in every mobile devices to block them access social media sites?
The objectives is have equal policy and protection for laptop and mobile devices. If facebook or X blocked via URL Filtering, we must blocking it as well in mobile devices application. Thank you!
Most mobile applications use certificate pinning, and they won't trust your certificate in the first place (facebook, reddit, ...).
If you'd like the devices to trust decrypted and resigned traffic, you'd have to install certificates on your mobile devices too. MDM solutions, such as InTune, AirWatch, etc can help with that. If you "only" would like to deny certain traffic/URLS, the mobile devices won't get to see the certificate you will be resigning with - so no need to install it, though you need to make sure you bypass allowed traffic, which in turn won't get inspected / resigned.
Thank you for your insight @oa_munich!
So, it is almost impossible to block mobile application via firewall, right?
I was thinking about cert pinning before, however, i am looking for any idea from CP firewall how to block such social media application and access social media via browser in mobile devices.
No, you absolutely can! The mobile device will attempt to open a connection to the target, the firewall would inspect it and block it. The mobile device won't get to see the inspected packets (which are decrypted and re-encrypted using your certificate), therefore it won't need your certificate.
For the permitted traffic - if you intend to not only bypass what you inspect - you'd need to distribute your certificate, so mobile devices would trust the traffic you permit.
Personally, I dont know if that can work with the fw itself, never tested it, but we have a client that uses harmony mobile for mobile phones in particular and works really well with https inspection, as they used MS intune to distribute the cert that way to the users' phones.
Andy
While you will get better (more accurate) results with HTTPS Inspection, you can certainly block certain kinds of traffic without it as the App Control/URLF policy reads the SNI of the relevant traffic.
Make sure you block QUIC in the policy.
@PhoneBoy wrote:Make sure you block QUIC in the policy.
Btw, according to the release notes:
Not sure what this means exactly, but QUIC seems to be partially inspected in R82 now.
We have support for QUIC in R82, yes.
However, I presumed the original poster isn't yet running R82.
nice
Yes, I tested it in the lab, works well.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 29 | |
| 15 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY