- CheckMates
- :
- Products
- :
- General Topics
- :
- HTTPS Inspection and Outlook Preview
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HTTPS Inspection and Outlook Preview
Hi, I have a customer running HTTPS-inspection, and they have a strange problem.
When HTTPS-inspection is active, most of the pictures in the Outlook preview pane are not shown (some are, but maybe 75% are not). This means that in most newsletter, all pictures are just shown as a small red cross.
If I then copy that picture-link directly from the mail, and paste it into a browser, it shows just fine, even though HTTPS-inspection is still active.
If I completely disable HTTPS-inspection, all the pictures in the Outlook preview are show.
Nothing is red (drops/rejects) in the log.
Has anyone seen this before or have any idea what's going on?
As far as I can read, the Outlook Preview pane uses same settings as the Microsoft browser. And since some pictures are shown, I don't expect it to be a certificate-error - I would also expect it to use the same CA-store as the browsers.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What does your HTTPS inspection policy look like?
Are you running R81.10 JHF T110 or something else here?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
It's a pretty normal policy.
A lot of bypasses, mainly based on dst-ip, but also domains and updatable objects. Then ending with a rule to inspect everything else from the private ip-adresses.
SmartCenter is running R81.20 jumbo 38 and the cluster is running R81.10 Jumbo 66, I think.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Most likely we'd need to run debug (and possibly a tcpdump) while the relevant page is loading to see what the issue is.
This will most likely require TAC assistance: https://help.checkpoint.com
