There is another way to block https pages without https inspection by doing this via DNS. Unfortunately this is not possible with Check Point technology. So I don't want to go into more detail here. When I have this requirement in projects, I use a product that does that at DNS level.
Either it returns the original IP address of a DNS request or for dangerous content, a fake IP address of a blockpage page is returned.
I will not write the manufacturer name in this forum:-)
Search goggle for "opendns umbrella"
➜ CCSM Elite, CCME, CCTE ➜