Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
maxtaan
Contributor

HTTPS inspection utilization impact

I want to enable HTTPS inspection to enable DPI in the maestro environment. Before that, I need to clear some queries.

1. If HTTPS inspection is enabled then what is the impact on CPU+Memory utilization?
2. Is it possible to install various types of certificates like wildcard, SSL, and so on for various services?
3. If I enable the HTTPS inspection blade, does it automatically inspect both inbound and outbound traffic? If yes, then is there any option to separate?

Please provide the official document/SK regarding these queries. Thanks

0 Kudos
9 Replies
Chris_Atkinson
Employee Employee
Employee

We now publish HTTPS numbers on the datasheets for 9000 / 19200 / 29200 appliances.

Inbound vs outbound is controlled separately, please refer to the documentation:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...

https://support.checkpoint.com/results/sk/sk65123

https://support.checkpoint.com/results/sk/sk108202

CCSM R77/R80/ELITE
Lesley
Leader Leader
Leader

https://support.checkpoint.com/results/sk/sk65123

Is there a performance impact when enabling HTTPS Inspection on the gateway?

HTTPS Inspection requires the Security Gateway to perform extra SSL work:
  • SSL handshake with the secure web site and with the client browser.
  • Decrypt & re-encrypt all SSL traffic, to be able to inspect it.

This has some performance impact on SSL capacity and latency, but in normal situations the end user should not be aware of it.

 https://support.checkpoint.com/results/sk/sk108202

(Part 4) Performance

Show / Hide this section

HTTPS Inspection creates additional load on Security Gateway's CPU and increased RAM usage due to these reasons:

TLS termination, encrypt/decrypt and active TCP termination.

Additional traffic is inspected by security blades.

In general, the more blades and security features, the higher the additional load.

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
maxtaan
Contributor

Thanks, @Lesley  , You have answered only one question from the three that I raised. Can you please answer the rest two the way you answered the first one?

0 Kudos
Lesley
Leader Leader
Leader

The rest you can find in the links that Chris posted above

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
the_rock
Legend
Legend

1. If HTTPS inspection is enabled then what is the impact on CPU+Memory utilization?

For powerful firewalls, you wont see much impact at all.


2. Is it possible to install various types of certificates like wildcard, SSL, and so on for various services?

Yes, they are, see point 23

https://support.checkpoint.com/results/sk/sk65123


3. If I enable the HTTPS inspection blade, does it automatically inspect both inbound and outbound traffic? If yes, then is there any option to separate?

No it does NOT, they are totally separate and inbound inspection needs its own cert (.p12 format) imported.

Andy

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Regarding point 1 this is subjective and version relevant, less of  an issue as of R81.20 but not insignificant by any means.

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

Yep, agree, ssl inspection is best in R81.20, no doubt about it. So far, R82 EA seems okay, but lets wait till its GA.

Andy

0 Kudos
PhoneBoy
Admin
Admin

Outbound inspection requires a CA certificate trusted by your clients to be used.
(Which means it cannot be used for people outside your organization)

For inbound inspection, you use the same certificate as your server.
If you're protecting multiple sites using the same public IP, you will need to use a single certificate that covers all the relevant FDQNs.

the_rock
Legend
Legend

@maxtaan 

To add to what @PhoneBoy said, you can also refer to my post below, hope it helps.

Best and if you need help, happy to help you in the lab with it, as I have fully working R81.20 and R82 ssl inspection lab. 

Andy

https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-tip/m-p/219139

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events