Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ProxyOps
Contributor

SmartConsole is using TLS 1.0 to connect via proxy to sc1.checkpoint.com

Hello all,

 

we tried to troubleshoot the reason why our Check Point SmartConsole R81 never shows when there is an update available. We followed the following guide to find  the issue:

Automatic updates for SmartConsole (checkpoint.com)

 

In C:\ProgramData\Check Point\SmartConsole R81.10 we found the mentioned .xml file:

 

<?xml version="1.0"?>
<UpdateStatus xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
  <State>NoInfo</State>
  <LastSuccessfulUpdate>0001-01-01T00:00:00</LastSuccessfulUpdate>
  <LastUpdateCheck>2023-04-19T18:21:03.1995339+02:00</LastUpdateCheck>
  <UpdateCheckError>FDT_ERROR</UpdateCheckError>
</UpdateStatus>

 

 

We are using a proxy to connect to the internet. The Check Points URLs are whitelisted and don't get intercepted. We did some tcpdumps and found the reason why the Smart Console is not getting a connection:

 

20230419_.jpg

Our proxy is rejecting the TLS 1.0 connection (which is expected and correct). Why is SmartConsole using TLS1.0 and how can we change it to something like TLS1.2 upwards?

 

Any help is would be welcomed.

 

Best regards

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

Pretty sure this is an RFE that should be discussed with your local Check Point office.
However, it might be worth a TAC case to confirm: https://help.checkpoint.com 

0 Kudos
the_rock
Legend
Legend

Not sure if below setting in global properties would be related, but worth checking.

Andy

Screenshot_1.png

0 Kudos
Dan_Zaidman
Employee
Employee

Hi @ProxyOps , thank you for bringing it to our attention.

The TLS 1.0 connection is not related to the update notification problem.

We will release a new SmartConsole jumbo for versions R80.40 to R81.20 that will not send that TLS 1.0 connection.

Regarding the update notification problem, we would like to set a short zoom session, in order to find the root cause.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events