- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear Mates
We wish to enable https inspection on our environment, but there are some privacy concerns. Thats why I am writing this post to get some feedback from the community. I am not worried about how it is done, I am would like to know if answers to the questions below:
There is currently a need to get https inspection working, but I need to have answers to questions that may be raised at the C level. We intend to start with the Outbout Inspection first.
Thanks in advance
1 - No user credentials are shown in the logs.
2 - You can't see the decrypted information on the gateway and it's not stored at all, only handled by the processes during inspection.
It would be nice to have a statement from Check Point on how the clear text data is protected while doing HTTPS Inspection, I guess that at some point is ""accessible"" in memory at least for some daemons.
Having said that and knowing Check Point philosophy I'm pretty sure that it's not accessible by users.
In the end it all depends on your C level of psychosis (AKA risk tolerance). If we speak about risk, not having HTTPS Inspection is far more riskier than worrying about credential sniffing in a hardened OS that performs that function.
Remember that you can bypass various categories.
___
Some customers have regulatory obligations that prevent them from dumping decrypted traffic in cleartext. We are currently testing a new scheme that addresses this concern.
In particular, a Check Point Azure VMSS is performing HTTPS Inspection, and using Mirror and Decrypt to dump the decrypted traffic to a Check Point NDR sensor for advanced threat analysis, behavioral analytics, and selective packet capture. This is performed over Large Scale VPN (LSV) to deliver end to end IPsec protection for the dumped traffic in transit. LSV allows the scale set to expand (or contract) without requiring policy installation on the NDR sensor.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY