Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Vladimir
Champion
Champion
Jump to solution

UserCheck portal using Certificate not created for HTTPS inspection

For the gateway configured to perform HTTPS inspection, with certificate created and distributed to clients, normal traffic behaves as expected:

But when UserCheck is encountered in the rulebase, the gateway serving its VPN certificate:

Which, as it happens, was not distributed to internal hosts.

Is there a way to address it properly?

1 Solution

Accepted Solutions
Norbert_Bohusch
Advisor

Yes, on the cluster/gateway properties under UserCheck you can enter the FQDN for UserCheck Portal and import a proper certificate matching it.

For sure FQDN must be resolvable to Cluster/Gateway IP.

View solution in original post

5 Replies
Norbert_Bohusch
Advisor

Yes, on the cluster/gateway properties under UserCheck you can enter the FQDN for UserCheck Portal and import a proper certificate matching it.

For sure FQDN must be resolvable to Cluster/Gateway IP.

PhoneBoy
Admin
Admin

Just to clarify, the UserCheck portal serves it's own certificate that is not subject to HTTPS Inspection (if I recall correctly).

Thus that certificate needs to be correct/something the client is configured to accept.

It would definitely be better if we could leverage the HTTPS Inspection CA in this case Smiley Happy

(1)
Vladimir
Champion
Champion

Agree with you on idea of using same cert for multiple purposes. It would actually be nice if the CA on SMS would've been a bit more functional with good front end. Some environments do not have PKI in place and could've used Check Point for this purpose.

0 Kudos
PhoneBoy
Admin
Admin

The front end of the Internal CA is called SmartConsole Smiley Happy

Granted, it's not meant as a full CA but for specific functionality, which could potentially be expanded.

0 Kudos
Vladimir
Champion
Champion

Smiley Happy good one

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events