- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
As full HTTPS inspection was introducing too many issues for us, we decided to go with "Categorize HTTPS websites" setting enabled in Application Inspection settings.
However, we would still like to match custom URLs for http and https service by using "Custom site" objects in the policy.
We did some tests and the results are not very consistent, we have the following behavior:
- works correctly, policy matches, https traffic is allowed
- works only on the second https access to same site, the first one is blocked (no match)
- not working at all because the https site is using a certificate signed by their own CA (eg. RedHat subscription network)
So we were ending up using domain objects, although I would have preferred custom url because of possible wildcard/regex.
So my questions would be:
Hi, reply to myself:
I found this interesting post, pointing out some the issues I've also found:
URL filtering without HTTPs inspection
I would really like to see subjectAltName property implemented in URL filtering!
Hi,
We created HF for supporting SNI with 'categorize https sites' on top of R80.10 GW version.
Please contact me directly if this is interesting you (meitalna@checkpoint.com).
Thanks,
Meital
Hello do you need any special configuration for that HF to work??
Hi,
The HF exists on top of R80.10 JHF T70.
Please contact me directly if you want to install it.
Thanks,
Meital
Hi,
In categorize https sites we use the DN from the certificate in order to match the traffic.
It should also work with custom urls and wild cards.
If the 'first connection' is not behaving like the next connections, check your categorization mode settings - you might want to change from background to hold.
we are not doing certificate inspection, but we are planning to support SNI categorization (we already have HF on top of R80.10 that support SNI).
If this might help you please contact me directly - meitalna@checkpoint.com.
Thanks,
Meital
@Meital_Natanson this is a very old topic and I'm not even sure if you're still working with it. But what is the latest status of HTTPS categorization in R80.40? Is it possible to create custom sites using regex and wildcards?
I'm reading sk106623 and it says which basically says it's not possible for "HTTPS lite"
Important: Never use Regular Expression (Regex) for HTTPS websites when not using HTTPS inspection.
I can tell you from my own experience, that this is working in R80.40. We are using it that way on multiple gateways.
You only have to take care, that the HTTPS Inspection Trusted CA List is up to date and contains all Root CAs of the sites you want to use "HTTPS Inspection Lite" a.k.a. "Categorize HTTPS websites" with. This list is used, even if "HTTPS Inspection" (the full one) is not enabled on the gateway.
thanks @Tobias_Moritz at the ended I worked out the syntax and actual content that had to go into regex! 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY