cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted

White Paper - URL Filtering using SNI for HTTPS websites

Author

@Kevin_Jones 

Abstract

The document describes how to leverage Server Name Indication (SNI) when using URL Filtering Software Blade.

 

For the full list of White Papers, go here

22 Replies
Vladimir
Pearl

Re: White Paper - URL Filtering using SNI for HTTPS websites

@Kevin_Jones , thank you for a brief and concise document describing SNI filtering functionality. Many of my clients can benefit from reading it.

In regards to its general availability: your document is from December of last year. When is this functionality will be available in R80.20 by JHFA?

Thank you,

Vladimir

Employee+
Employee+

Re: White Paper - URL Filtering using SNI for HTTPS websites

R80.30

0 Kudos

Re: White Paper - URL Filtering using SNI for HTTPS websites

Is this functionality will be available in R80.20 by JHFA???
Considering right now R80.20 is the recommended version
0 Kudos

Re: White Paper - URL Filtering using SNI for HTTPS websites

Is that available in R80_10_JUMBO_HF?
0 Kudos

Re: White Paper - URL Filtering using SNI for HTTPS websites

And SNI visibility with tls 1.3?

https://blog.cloudflare.com/encrypted-sni/
Employee+
Employee+

Re: White Paper - URL Filtering using SNI for HTTPS websites

For URL filtering this is on by default
I am told that NG bypass does not require any extra configuration I am still validating
0 Kudos
Vladimir
Pearl

Re: White Paper - URL Filtering using SNI for HTTPS websites

@Uri_Lewitus , did you get the chance to validate this?

Thank you,

Vladimir

0 Kudos
RickLin
Silver

Re: White Paper - URL Filtering using SNI for HTTPS websites

Can CheckPoint teach us how to use "Next Generation Bypass"? 

Thanks for clarification.

0 Kudos

Re: White Paper - URL Filtering using SNI for HTTPS websites

That is part of this White Paper - URL Filtering using SNI for HTTPS websites !

0 Kudos

Re: White Paper - URL Filtering using SNI for HTTPS websites

Is this functionality already available in R80_10_JUMBO_HF?? thanks

0 Kudos

Re: White Paper - URL Filtering using SNI for HTTPS websites

As of now, this is a separate HF that goes on top of T154.

0 Kudos

Re: White Paper - URL Filtering using SNI for HTTPS websites

Great information!

I have two qustions:

1) Can anyone confirm is the following feature is included in the new engine of SSL Inspection in R80.30? R80.30 doesn't need the probe bypass feature since it checks de Client Hello and the certificate. Also, it works with Categorize HTTPS without SSL Inspection and without turning on the kernel parameters? I'll try to check this later in a lab enviroment.

"Using this field, rather than relying on the CN of the certificate, gives more specific and accurate information about the requested site. The recently released hotfix for Check Point R80.10 gateways does change this behavior and utilize the SNI extension for categorization. Once installed, the feature can be enabled with the following command: fw ctl set int urlf_use_sni_for_categorization 1 This hotfix also allows a further check to make sure that the SNI requested by the client matches one of the SAN entries on the certificate. To enable this feature, use this command: fw ctl set int urlf_block_unauthorized_sni 1"

2) Is there any benefit in having "Categorize HTTPS sites" AND Outbound SSL Inspection? There are many posts that state that they are mutually exclusive, but in R80.20+ you can have both turned on. So far in my testing I could not see any benefits. Maybe it doesn't inspect all the https traffic?

Thanks!

Federico Meiners

https://www.linkedin.com/in/federicomeiners/
0 Kudos
Vladimir
Pearl

Re: White Paper - URL Filtering using SNI for HTTPS websites

@FedericoMeiners , the SSL categorization is there simply to improve the Application Control and URL filtering. SSL inspection actually allow the payload to be analyzed by other TP blades as well as Content Control and DLP.

0 Kudos

Re: White Paper - URL Filtering using SNI for HTTPS websites

@Vladimir I know that, but what is the effect/advantage of having Outbound SSL Inspection + HTTPS Categorization? You can turn them both in R80.20+
https://www.linkedin.com/in/federicomeiners/
0 Kudos
Vladimir
Pearl

Re: White Paper - URL Filtering using SNI for HTTPS websites

Consider, for instance, the situation when you are exempting certain traffic from SSL inspection based on its categories, i.e. financial and health.

Re: White Paper - URL Filtering using SNI for HTTPS websites

I see here many questions about SNI enhancement availability with R80.20.

As fas as I am concern, R80.20 can have SNI functionality back-ported, with a special HFA, with is not part of the regular Jumbo. 

@Oren_Segev, can you please give more details?

Re: White Paper - URL Filtering using SNI for HTTPS websites

Could someone please confirm if this functionality works on R80.20? thanks

0 Kudos

Re: White Paper - URL Filtering using SNI for HTTPS websites

Any idea when this functionality (URL Filtering using SNI for HTTPS websites) will be available for Gaia Embedded (7xx/14xx)?
0 Kudos
Tom_Hinoue
Nickel

Re: White Paper - URL Filtering using SNI for HTTPS websites

Hi Miguel,

In matter of fact, SNI for APPI/URLF it is already available on Gaia Embedded on recent firmwares (disabled by default) in locally managed mode.

Go to Device -> Advanced Settings and find [Application Control and URL Filtering - Custom App over HTTPS].
Enable the parameter and you're good to go.

enabling_SNI_INS_on_embedded.PNG

Re: White Paper - URL Filtering using SNI for HTTPS websites

Thanks @Tom_Hinoue!
What about centrally managed mode?
0 Kudos

Re: White Paper - URL Filtering using SNI for HTTPS websites

Hi @Tom_Hinoue ,

Which version are you running on this picture? 

I'm running Embedded GAIA R77.20.87 - Build 960 and I wasn't able to see this parameter Custom App Over HTTPS as shown below 


SMB Appliance.jpg

 
 
0 Kudos
Tom_Hinoue
Nickel

Re: White Paper - URL Filtering using SNI for HTTPS websites

Hi @felipetropeia,

This feature is only available currently on Locally Managed mode of SMB appliances since R77.20.80+, and not Centrally Managed mode as what I believe you are using now from your provided image. (and apologies to @Miguel_Barrios for missing your post)

From what I know that SNI is available on R80.10+ in latest Jumbo Hotfixes on maintrain, I believe SNI on Centrally Managed Gaia Embedded which runs on R77 code is not compatible with SNI inspection yet (some one correct me if I'm wrong)

Staring the new 1550/1590 the OS now runs on R80.20 code, so maybe we can expect SNI for Centrally Managed soon 🙂