- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hey again guys!
Can the Check Point forward certain http/s requests to a peer proxy?
We require traffic to certain http/s domains to be forwarded to our head office "peer proxy" in order for our users to access head office sites.
Currently we use our in-line explicit proxy to forward this http traffic that matches a "head office" list of domains to our peer proxy server at head office. All the matching http/s traffic is forwarded to this other peer proxy over an existing S2S Check Point VPN (Check Point on both ends).
Can we configure our Check Point to forward this pre-defined http/s traffic to this Head Office peer proxy so we can loose our local proxy entirely?
Thank you again!
Hey brother,
Yes, it can. Besides post Phoneboy referenced, here are some other great links.
https://support.checkpoint.com/results/sk/sk103086
I know this one if Forcepoint, but relevant -> https://support.forcepoint.com/s/article/000013312
Doesn't the new "Proxy Chaining" feature introduced in R82 do what you want? See Section 5 of sk110013: How to configure Check Point Security Gateway as HTTP/HTTPS Proxy:
Starting from the version R82, you can configure Proxy Chaining on Security Gateways to forward outbound IPv4 HTTP/HTTPS traffic to an upstream proxy server based on URL patterns.
This enables a Security Gateway to support multi-layered proxy architectures for compliance, monitoring, or traffic routing purposes.
You configure the applicable proxy settings and rules on the Security Gateway in the "$FWDIR/conf/upstream_proxy_policy.txt" file.
@Peter_Elmer created a video about this: https://community.checkpoint.com/t5/Security-Gateways/Hands-On-Quantum-Network-Firewall-as-Web-Proxy...
Hey brother,
Yes, it can. Besides post Phoneboy referenced, here are some other great links.
https://support.checkpoint.com/results/sk/sk103086
I know this one if Forcepoint, but relevant -> https://support.forcepoint.com/s/article/000013312
@Joe_Kanaszka I believe not what you want to do. Yes, Check Point gateway can run as proxy for your clients.
You mentioned:
"explicit proxy to forward this http traffic that matches a "head office" list of domains to our peer proxy server at head office"
Sending a website with URL www.mycompany.com to proxy A and website with URL www.myowndomain.com to proxy B or the internet, this is'nt possible.
Beside of this and in my own experience, I would no more use the proxy feature of a Check Point gateway. It really slows down all connections going via proxy, Because all of these connections can't be accelerate by SecureXL.
sk92482 - Performance impact after enabling HTTP/HTTPS Proxy on Security Gateway
Proxy feature all the time results in some memory leaks. Some authentications can't be passed through the proxy....
See sk110013 - How to configure Check Point Security Gateway as HTTP/HTTPS Proxy
I would really do a deep testing PoC beofre going in production. I prefer using a dedicated product for such a feature. (SQUID does everything for us)
Thank you Wolfgang!
What you are describing sounds exactly like what we would like to do.
Just to clarify...
We would like all URLs that are meant for our Head Office to get forwarded to the peer Head Office Proxy A.
All other URLs NOT meant for Head Office we like to send to our own Proxy B and NOT be forwarded to any peer.
This is NOT possible correct?
Thank you again!
Doesn't the new "Proxy Chaining" feature introduced in R82 do what you want? See Section 5 of sk110013: How to configure Check Point Security Gateway as HTTP/HTTPS Proxy:
Starting from the version R82, you can configure Proxy Chaining on Security Gateways to forward outbound IPv4 HTTP/HTTPS traffic to an upstream proxy server based on URL patterns.
This enables a Security Gateway to support multi-layered proxy architectures for compliance, monitoring, or traffic routing purposes.
You configure the applicable proxy settings and rules on the Security Gateway in the "$FWDIR/conf/upstream_proxy_policy.txt" file.
Good morning Timothy and thank you!
This is good to know as we'll be upgrading to R82 this summer.
So to reiterate my question to Wolfgang above:
"Just to clarify...
We would like all URLs that are meant for our Head Office to get forwarded to the peer Head Office Proxy A. These "Head Office" URLs are maintained in a static config file that resides on our proxy server.
All other URLs NOT meant for our Head Office we like to send to our own Proxy B and NOT be forwarded to any peer."
On top of this "Proxy Chaining" feature, we would also require URL filtering to block company-deemed inappropriate sites.
Could we accomplish all this on R82?
Thank you again Timothy!
@Joe_Kanaszka with these new information this should work. URL-filter with proxy is no problem.
Thanks @Timothy_Hall . These are good and very interesting news, never heard about this new feature. Maybe the reliability of the proxy feature will be better with R82. I'll give it a chance in an upcoming project.
I believe regarding the performance problems nothing changed, because the traffic starts from gateway and this won't be accelerated?
Correct, traffic originating from the gateway remains in slowpath.
Excellent video by Tim Hall about what Phoneboy mentioned.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 10 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY