Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
maxtaan
Contributor

HTTPS inspection utilization impact

I want to enable HTTPS inspection to enable DPI in the maestro environment. Before that, I need to clear some queries.

1. If HTTPS inspection is enabled then what is the impact on CPU+Memory utilization?
2. Is it possible to install various types of certificates like wildcard, SSL, and so on for various services?
3. If I enable the HTTPS inspection blade, does it automatically inspect both inbound and outbound traffic? If yes, then is there any option to separate?

Please provide the official document/SK regarding these queries. Thanks

0 Kudos
2 Replies
Chris_Atkinson
Employee Employee
Employee

We now publish HTTPS numbers on the datasheets for 9000 / 19200 / 29200 appliances.

Inbound vs outbound is controlled separately, please refer to the documentation:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...

https://support.checkpoint.com/results/sk/sk65123

https://support.checkpoint.com/results/sk/sk108202

CCSM R77/R80/ELITE
Lesley
Advisor
Advisor

https://support.checkpoint.com/results/sk/sk65123

Is there a performance impact when enabling HTTPS Inspection on the gateway?

HTTPS Inspection requires the Security Gateway to perform extra SSL work:
  • SSL handshake with the secure web site and with the client browser.
  • Decrypt & re-encrypt all SSL traffic, to be able to inspect it.

This has some performance impact on SSL capacity and latency, but in normal situations the end user should not be aware of it.

 https://support.checkpoint.com/results/sk/sk108202

(Part 4) Performance

Show / Hide this section

HTTPS Inspection creates additional load on Security Gateway's CPU and increased RAM usage due to these reasons:

TLS termination, encrypt/decrypt and active TCP termination.

Additional traffic is inspected by security blades.

In general, the more blades and security features, the higher the additional load.

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events