- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello dears
I have a problem downloading some https sites
What happens is that first the site appears blocked as shown in the following image, but after a few seconds it loads without problems
We have a Cluster HA running R81
I would be very grateful for help in finding the reason.
Thank you in advance
Please provide the following:
- JHF Take?
- HTTPS inspection enabled? Y/N
- If yes how is the HTTPS inspection rule base configured?
- Trusted CAs updated?
- Is fail-close used?
- Is hold mode used?
Unfortunately your attachments aren't working...
Note the latest GA JHF take includes the following fixes amongst others.
PRJ-31694, PMTR-73790 |
IPS | Improved the handling of decoded HTTP/S traffic. |
PRJ-29476, PMTR-72234 |
SSL Inspection | In some scenarios, a memory leak may occur when creating ECDHE keys. |
PRJ-30460, PRHF-19516 |
SSL Inspection | In rare scenarios, HTTPS connections may hang indefinitely during the TLS handshake, causing timeout. |
PRJ-30701, PMTR-72756 |
SSL Inspection, VPN |
A memory leak in HTTPS Inspection and HTTPS portals may occur when using ECDHE ciphers. |
An upcoming JHF Take will also include:
PRJ-30819, PRHF-19417 |
SecureXL | In a rare scenario, after an upgrade, HTTPS traffic may be dropped. |
You could try upgrading to the latest GA JHF or contact TAC to diagnose further.
Hi Chris, I will try with the latest GA JHF, and check the behavior
Thank you
The first thing that came to my mind when I read your post was https inspection. Can you disable it and test to see if same issue happens?
Andy
Hi Andy, thanks for your response
It is not possible because it is a critical service
Not even in a short maintenance window? That would take literally 10 mins tops.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY