Hello Checkmates,
As we were using HTTPS Inspection of Internet traffic quite successfully, without many issues, we recently started to do HTTPS Inspection on Inbound traffic towards one of our Web DMZ services.
For the last 1.5 - 2 months, everything works quite well, but we bumped into some "false positives" while checking the SSL health/security from SSLLabs portal.
Because the HTTPS traffic is terminated in Checkpoint, in order to be able to inspect it and do whatever else is necessary, it's accepting TLS1.0 & 1.1 even on our DMZ side we don't as we have minimum TLS 1.2 and 1.3 (max) .
To address this, we found 3 ways only (recommended by TAC as well):
- Drop the connections at the kernel level, which can be configured through GuiDBEdit.
This would affect not only the Inbound traffic – traffic from Internet to our DMZ that is HTTPS Inspected – but the Outbound traffic as well – traffic from internal clients to internet that is HTTPS Inspected. Therefore we can’t use this option.
- Enable the relevant IPS protection. However, since Autonomous Prevention is being used, this option is not applicable in the current setup.
We tried this, but because we are with Autonomous Threat Prevention, this is not possible as for the use of the IPS protections, we have to modify their actions and apply them into an IPS Policy. If we could do the changes to IPS protections and make use of those with the Autonomous Threat Prevention, it would be the best way to apply this.
- Use an Access Control rule to block the traffic. This is the approach you have already implemented according to the Administration Guide. However, due to the Protocol Signature behavior described above, the first few packets may still be allowed before the connection is blocked.
We tried this initially, and indeed the rule has hits, still it’s not acting for all traffic – we don’t understand why.
If we use ssllabs.com to scan our DMZ portal, we see that even we don’t allow TLS 1.0 and TLS 1.1 on our DMZ portal, Checkpoint terminates the SSL connections and the TLS 1.0 and TLS 1.1 are working and the SSLLabs portal detecting that, grades the security of the site lower – due to the TLS 1.0 and TLS 1.1 being accepted by Checkpoint. We understand that the Protocol Signature few packets are being allowed, we don’t see that the access rule we have created is blocking.
|
|
|
So the question to you is, can I get this without impacting Inbound HTTPS traffic ?
Is there something I missed in our settings/set-up?
Thank you,
PS: we have Checkpoint Maestro, with VSNext and Autonomous Threat Prevention on R82; and this weekend we'll have the latest JHF127 .