Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
keydee
Participant

HSTS Missing From HTTPS Server - Serv

Our checkpoint gateways is hosted in google cloud environment which uses r80.10. This is our first time to encounter an "HSTS Missing From HTTPS Server" vulnerability which came from the result of our vulnerability scanner. It targets the service 443 which I assume more on the gaia web. Could you kindly assist me on how can I find the configuration of this HSTS in either management server or gateway. Has anyone also tried to fix this in your checkpoint that are hosted also in a cloud environment. 

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Install the latest jumbo hotfix, which includes this configuration, or upgrade to a later version.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 

0 Kudos
_Val_
Admin
Admin

Missing HSTS is a cosmetic issue here. Gaia only allows HTTPS TLS connectivity in any case. However, if you want it fixed, please follow @PhoneBoy's directions 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events