Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
chethan_m
Collaborator

Checkpoint Gaia Web-UI HTTPS redirection and Enforce HSTS (HTTP Strict Transport Security)

Hi everyone,

 

I recently saw on one of the community posts that said, HTTP redirection is the default behavior on Checkpoint and no explicit configuration is required unlike Fortinet Firewalls. 

But when we try to connect to the Gaia Web-UI portal using only the server-IP-address but not HTTPS or http://<ip-address> then it refuses to connect, unless we explicitly specify https://<ip-address> (for the first time at least).  I don't see a redirection happening.

Am I missing out something? and can we enforce HSTS for Gaia Web UI by any chance? I believe, there must be configuration for this.

The requirements are:

  1. Checkpoint must instruct the web browser(s) to always connect to it via HTTPS.
  2. The Checkpoint's internal web server must provide the HSTS directives.
  3. Disable the ability for the users to click through TLS warnings.

 

Are these hardening requirements, overkill for just accessing the firewalls that are internal or a legitimate one?

 

Thank you.

 

Quantum Force (Security Gateways) Next Generation Firewall 

0 Kudos
3 Replies
_Val_
Admin
Admin

Can you refer to that post? Paltform portal does not do HTTP to HTTPS redirection, AFAIK. 

0 Kudos
chethan_m
Collaborator

0 Kudos
PhoneBoy
Admin
Admin

The only supported mechanism to access the Gaia WebUI is HTTPS.
We don't even listen on TCP port 80 any longer, thus we do not provide a mechanism to redirect from HTTP to HTTPS.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events