Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Jsaun
Participant

SSL Interception and offload to Proxy

Currently we have a proxy that is performing SSL Interception. This causes high CPU load so we want to move SSL Interception off of the Proxies. I know that Checkpoint r80x does this but is there a way to expose/decrypt the SSL traffic on the firewall, send it to the proxy to be evaluated against the proxy policy and then send it back to the firewall and re-encrypted on the Checkpoint?

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Check Point has a Mirror and Decrypt feature from R80.20 and up.
With this feature configured, you can either mirror traffic unencrypted or encrypted to a specific port on your gateway.
It is meant for a third-party Recorder or Packet-Broker that operates in monitor (promiscuous) mode to accept the mirrored and (possibly) decrypted traffic.
That means it won't work for your desired use case.

You realize Check Point can do App Control/URL Filtering too, right?
If you're having it decrypt the traffic, why not have it perform access control and threat prevention on it as well?

0 Kudos