- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi Team,
We have a 1900 spark appliance in Cluster version R81.10.10.
Requirement is to have APP & URL Blocking based on the predefined categories (e.g Shopping, FTP, Social, Media etc) with out HTTPS inspection as customer cannot install the certificates on endpoint and/or mobile devices.
We have tested to use HTTPS categorization but its not working as expected, few sites are getting blocked and some are working, hence not achieving the desired solution.
but when HTTPS inspection is configured all is working properly, the categories which are blocked in rule are not working which is desired.
Is there any other way to achieve this???
I would first install the current version R81.10.15 Build 996003913 and after testing, open SR# with CP TAC to get this resolved.
Do you have an explicit rule blocking QUIC in your rulebase?
QUIC traffic will not be categorized by HTTPS Categorization.
By blocking QUIC, the client web browsers should fall back to HTTP/1.1, for which traffic can be categorized correctly.
Yes, QUIC - but recently with 1600, blocking QUIC on GW did not help, so customer had to disable it for browsers using GPO.
Yes, we have explicit rule to block QUIC. Still categorisation is not working.
Any alternate solution?
HTTPS Categorization uses one two things to categorize websites for HTTP/HTTPS connections (QUIC connections aren't supported for HTTPS Categorization):
Specific examples of websites that should be being blocked but aren't might be helpful.
Categories example such as gambling, Shopping, Media, Youtube.
Amazon.in
flipkart.com
888.com
velonyx.live
and many more
To see if the problem is Encrypted SNI, you will have to take a packet capture when the client initiates a connection to this site.
If it's Encrypted SNI, the only solution to that is HTTPS Inspection.
If the SNI is not encrypted and it's not working, then I suggest a TAC case.
Hi Team,
Customer is having other Firewall as well such as Palo alto & sonicwall & same thing is working there without SSL/HTTPS inspections..
So here in Checkpoint its not working without Https inspections...
A TAC case will be necessary to investigate this issue further.
To accelerate the analysis - I would try Quantum centrally managed, SPARK centrally managed as well
(For simplicity VM version can be used. It will allow us to pinpoint where the problem is.
We have tried testing with Quantum centrally managed full Gaia in LAB (VM based) & there categorization is working properly, blocking is working as expected based on categories configured in rule.
But the same is not working with 1900 spark appliances with Local Management.
Can you confirm the browsers are configured the same in each test scenario, this site will be useful here:
https://www.cloudflare.com/ssl/encrypted-sni/#results
TAC is already raised but still not proper solution.
I had taken captures on Firewall, there was no encrypted SNI.
Hello,
Same issue, using current firmware version is R81.10.17 (996004653)
Is there any update regarding this ?
Thanks
If you have already tested with the equivalent of the following set for 'hold' instead of background then you should take it internally or with TAC.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
14 | |
7 | |
4 | |
4 | |
3 | |
2 | |
2 | |
2 | |
2 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY