- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hey guys,
Happy weekend 🙂
Apologies if I posted this in wrong space, but could not find management any longer listed anywhere.
Anywho, Im sure I asked this many times before, but since people CONSTANTLY keep asking me, I wanted to bring it up once more. Is there any way to somehow get a hit count enabled for https outbound inspection policy?
I tried writting a script, but no matter what I do, just does not give me what Im looking for.
Thoughts?
Tx as always for helping.
I did some search online and found out this is indeed implemented in R82.10, which I did confirm with demo smart console. Gateway would need to be on that version.
Open an RFE and ask your customers to do the same in consultation with their SE.
https://usercenter.checkpoint.com/ucapps/rfe/
Hey Chris,
I did that while back actually, but never received any feedback about it. I will keep trying and see if I can somehow make it work.
This slipped past me as well, as you say it's mentioned in the release notes for R82.10
All good brother...none of us are supermen/AIs/robots 😁
I did some search online and found out this is indeed implemented in R82.10, which I did confirm with demo smart console. Gateway would need to be on that version.
Funny - I've been looking at HTTPs inspection recently and wanted exactly the same thing i.e hitcount on outbound https policy.
Now - may not be specific to this thread, but the fact you need a SubCA certificate to do HTTPs inspect was also a challenge if I wanted this signed by the clients PrivateCA, basically there is no way they would do that.
I have however created a PrivateCA certificate using OpenSSL (in this way I can add more values to it), and then created a Server Certificate from this with SANs; This is then used for UserCheck.
In this way only the PrivateCA's public cert needs to be imported into the end users devices.
Happy to share the commands used for OpenSSL with the exact parameters that worked for me (Clearly changing the values though).
When testing the only issue I've seen, which is odd, was with cnn.com (have a TAC case open for this).
my HTTPs inspection policy also has all the updateable object with'bypass' in them, as well for Bypass. The SK related to this need to be updated with these additional value as its not been updated since around 2022 (send feedback on this to Checkpoint, via the SK).
Hey mate,
I tried so many times to see if there is guidbedit setting that can be modified to make this work, but no matter what I try, does not work. O well, now we know its present in R82.10. I still wont give up, will try to make it work on my lab. My mgmt is R82, but cluster is still R81.20, thats cluster where I have my lab win 11 machine "subjected" to ssl inspection.
Managed to figure out why cnn.com was not working, Checkpoint has not loaded the Chain certificate into the trust store, so I loaded it in the custom trust store and it worked.
I found a few others and reported them all to Checkpoint TAC so they can all be considered for the next certificate package update.
Thats great, thanks for that, @genisis__
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 13 | |
| 10 | |
| 8 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY