Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
denetworks
Explorer

Outbound HTTPS Inspection doesn't work randomly

Hello,

We have enabled HTTPS inspection to outbound connection to Internet. We've imported root CA certificate from windows domain in checkpoint firewall. It works fine mostly but sometimes, user's browsers show certificate warning page. In these cases, the loaded certificate is empty, it doesn't have a subject name. If we reload the page, it shows the correct certificate from checkpoint firewall without any warning or error.

Could it be a bug or misconfig?

Thanks.

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

What version/JHF on what hardware?
You may need TAC to assist in investigating this.

0 Kudos
denetworks
Explorer

HI, the version is R81.10 take 335

0 Kudos
Lesley
Leader Leader
Leader

please share cpinfo -y all output of problematic gateway. 335 is not correct take number. 

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Alex-
Leader Leader
Leader

335 is the baseline OS build, not a JHF Take.

 

Some-Gateway>show version all
Product version Check Point Gaia R81.10
OS build 335
OS kernel version 3.10.0-957.21.3cpx86_64
OS edition 64-bit
the_rock
Legend
Legend

Hey @denetworks ,

This is what we are referring to.

Andy

 

[Expert@cpazurecluster1:0]# cpinfo -y fw1

This is Check Point CPinfo Build 914000239 for GAIA
[FW1]
HOTFIX_R80_40_MAAS_TUNNEL_AUTOUPDATE
HOTFIX_GOT_TPCONF_AUTOUPDATE
HOTFIX_R81_20_JUMBO_HF_MAIN Take: 53
HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE

FW1 build number:
This is Check Point's software version R81.20 - Build 024
kernel: R81.20 - Build 032

[Expert@cpazurecluster1:0]#

0 Kudos
the_rock
Legend
Legend

I dont believe thats a bug. I recall having that issue once working with a customer and we did have TAC case open for it, but out of the blue, one day all just started working fine without a single change or version upgrade.

I can tell you, having tested https inspection who knows how many times in the lab, it works really well in R81.20. If you need me to test anything, happy to do it, I actually have windows PC thats behind the lab cluster, with inspection running, so not a problem to do any test.

Best,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events