Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sorin_Gogean
Advisor

Ways to Disable TLS 1.0 & 1.1 on Outbound HTTPS Inspection traffic

Hello Checkmates,

 

As we were using HTTPS Inspection of Internet traffic quite successfully, without many issues, we recently started to do HTTPS Inspection on Inbound traffic towards one of our Web DMZ services. 

For the last 1.5 - 2 months, everything works quite well, but we bumped into some "false positives" while checking the SSL health/security from SSLLabs portal. 

Because the HTTPS traffic is terminated in Checkpoint, in order to be able to inspect it and do whatever else is necessary, it's accepting TLS1.0 & 1.1 even on our DMZ side we don't as we have minimum TLS 1.2 and 1.3 (max) .

 

To address this, we found 3 ways only (recommended by TAC as well):

  1. Drop the connections at the kernel level, which can be configured through GuiDBEdit.

    This would affect not only the Inbound traffic – traffic from Internet to our DMZ that is HTTPS Inspected – but the Outbound traffic as well – traffic from internal clients to internet that is HTTPS Inspected. Therefore we can’t use this option.
  2. Enable the relevant IPS protection. However, since Autonomous Prevention is being used, this option is not applicable in the current setup.

    We tried this, but because we are with Autonomous Threat Prevention, this is not possible as for the use of the IPS protections, we have to modify their actions and apply them into an IPS Policy. If we could do the changes to IPS protections and make use of those with the Autonomous Threat Prevention, it would be the best way to apply this.
  3. Use an Access Control rule to block the traffic. This is the approach you have already implemented according to the Administration Guide. However, due to the Protocol Signature behavior described above, the first few packets may still be allowed before the connection is blocked.

    We tried this initially, and indeed the rule has hits, still it’s not acting for all traffic – we don’t understand why.
    If we use ssllabs.com to scan our DMZ portal, we see that even we don’t allow TLS 1.0 and TLS 1.1 on our DMZ portal, Checkpoint terminates the SSL connections and the TLS 1.0 and TLS 1.1 are working and the SSLLabs portal detecting that, grades the security of the site lower – due to the TLS 1.0 and TLS 1.1 being accepted by Checkpoint. We understand that the Protocol Signature few packets are being allowed, we don’t see that the access rule we have created is blocking.
Screenshot 2026-10-07 091506.png

 

 
Screenshot 2026-10-07 091610.png

 

 

So the question to you is, can I get this without impacting Inbound HTTPS traffic ? 
Is there something I missed in our settings/set-up?

 

Thank you,
PS: we have Checkpoint Maestro, with VSNext and Autonomous Threat Prevention on R82; and this weekend we'll have the latest JHF127 . 

 

 

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

0 Kudos
Sorin_Gogean
Advisor

Hello @PhoneBoy ,

That we already have it set with TLS1.2 and it does not influence HTTPS Inspection of Inbound traffic.

Thank you and have a nice week,

0 Kudos
Ruan_Kotze
MVP Gold
MVP Gold

Hi Sorin,

The documentation is vague and and one might say even say incomplete for inbound inspection, we've had to resort to GuiDBedit to manipulate the minimum versions the gateways will accept.

My observations:

  • The gateways obeys the ssl_min_ver parameter. You can raise the min_ver to 1.1 or 1.2 and it will be reflected after you push policy
  • Conversely, ssl_max_ver is not obeyed. 1.2 is the highest setting but even so the gateway will still accept TLS 1.3
  • We were unable to manipulate the TLS levels successfully either with cipher_util. IPS or protocols in the access policy.

For your scenario you need to set the ssl_min_ver parameter to whatever your minimum is  You do this like so:

  1. GuiDBEdit, on the tables tab, select Other - ssl_inspection
  2. In the Objects column, select geberal_confs_obj
  3. In the Fields columnm select the minimum and maximum TLS version values (min will be obeyed, max not)

Once done and policy pushed, give it a minute or two then your SSL Labs test should reflect the change.

-Ruan

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events