- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Does HTTPS Inspection support RDP over Https?
I tried to activate Inbound HTTPS inspection on our RDP gateway which allows opening RDP connections over HTTPS on port 443.
The session is opened using https from an external client to the session broker and then changes to RDP over https (similar to the image below).
When activating the https inspection, the connection is broken and there is a log saying that
When bypassing the connection in the Https inspection policy, RDP is working again
Is it possible to inspect such connections?
Did anyone try and succeed?
Is there a way to workaround the broken session or to inspect only the connection initialization (which is HTTPS only before changing to RDP)?
If not, is there a plan to support RDP over HTTPS inspection in the future?

SSL Config of the Web Server would be interesting, i think.
i.e. here - https://community.checkpoint.com/thread/7700-https-inspection-problem-about-unspoorted-ssl-version it is stated that SSLv3 is disabled by default, which might result in your message...
Also, is there a publicly trusted certificate in use or from internel PKI/self signed? Does yout Firewall trust the issuer of these certs?
Daniel
There should be log messages in SmartLog if the TLS negotiation is failing somehow.
My question is why legitimate RDP traffic should be inspected anyhow...
As far as I unterstood, it‘s more for the rdp over https from Internet to the rd Gateway/Broker (however MS is calling it) which is then kind of reverse proxying the rdp to the Terminal Server.
so for the Gateway it‘s a https connection.
Daniel
Correct Daniel, I would like to scan the https/RDP to traffic to make sure that the connection opened to the session broker and to the remote desktop session host is legit. If it is not possible to scan the RDP protocol, I would at least expect to be able to scan the HTTPS part (Where the connection is opened from the client to the session broker using HTTPS) and to be able to bypass the RDP over HTTPS traffic.
If this is not supported it is a good RFE to be able to scan RDP over HTTPS in future versions
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY