- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Everyone!
We have a use case where we need to deploy inbound HTTPS Inspection to a specific web service that uses a non standard port.
Gateways and management are both running R80.40.
Initially we are seeing a Bypass with the following error "Internal system error in HTTPS Inspection (Error Code: 2)"
One of the possible causes is that the root certificate is not trusted, however the customer is using the same cert in other inbound inspection rules without issues.
While troubleshooting we found that the backend application requires the client to send a specific certificate.
Since we are doing a Man-in-the-middle (MITM) for inspection it's obvious that the connection between the Gateway and the server will have the Check Point self signed certificate, not the one required by the application.
I know that this use case can be solved with an ADC such as F5, Netscaler, A10.
Questions:
- Can we do it with Check Point? I didn't find a proper way of using specific client certificates (Not server certs) for specific connections within the admin guides or SKs.
- Can "Internal system error in HTTPS Inspection (Error Code: 2)" be related to this issue? An HTTPS debug is not possible for the moment due to maintenance window requirements.
Thanks!
AFAIK, we do not have such functionality available. Try raising and RFE with your local Check Point team. Meanwhile, you will have to create a bypass rule for this application to work
AFAIK, we do not have such functionality available. Try raising and RFE with your local Check Point team. Meanwhile, you will have to create a bypass rule for this application to work
Valeri,
Thanks for the quick response! Just wanted to be sure of my assumptions.
It would be nice feature however it's not the job of a NGFW 🙂
Will work on the RFE with my local SE.
Thanks!
Federico
I know this thread is maybe already outdated,
but i'm very interested in case there was a response to the RFE.
I do have a similar requirement.
* HTTPS inbound inspection should be used to inspect traffic.
* Server requires certificate based client authentication
My quick check:
Server tcpdump:
- Server Hello, Certificate, Certificate Request, Server Hello Done
Server Application Log:
- HTTPS client connection from host {FW-IP} failed due to the SSL error:
(sec.core-114) SSL connection error (peer did not return a certificate).
The behavior is, that this connection will time out.
Firewall log doesn't show Error Code-2
(what is in my experience mostly missing CA cert in list of Trusted CA or failed OCSP/CRL check)
Our competitor PA offers for such cases an interesting "nonProxy / forwarding mode".
As they have the private key and key exchange is RSA (not PFS),
then the firewall can simply copy and decrypt the https traffic for inspection. (PA is not MITM)
SSL Inbound Inspection (paloaltonetworks.com)
Does Check Point support such a mode?
@FedericoMeiners: Did you raised an RFE?
Thanks,
Ciao Martin
I believe as part of our NDR offering we have something that can do this.
The feature is called Cooperative Inspection.
Note that NDR sensors run a different image and are managed differently from regular Check Point gateways.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 14 | |
| 10 | |
| 9 | |
| 7 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY