Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
lluner
Advisor

Checkpoint inspection https and http

hi 

 

How do I do this in Checkpoint? Is it possible to associate port 443 only with the HTTPS protocol or not allow the SSH protocol on port 443?

0 Kudos
7 Replies
Chris_Atkinson
Employee Employee
Employee

Please review Protocol signatures option & HTTPS inspection for this requirement.

iirc there was also an IPS protection for SSH over non-standard ports as an alternative but please double-check the performance implications of this approach.

CCSM R77/R80/ELITE
0 Kudos
AkosBakos
Leader Leader
Leader

Hi,

Create a custom service object, and set it as @Chris_Atkinson  said.

You can choose the protocol (1st screenshot)

2024-12-29 18_28_48-Cloud Demo Server [ID_784674684]-R81.20-SmartConsole.png

2024-12-29 18_29_05-Cloud Demo Server [ID_784674684]-R81.20-SmartConsole.png

Akos

----------------
\m/_(>_<)_\m/
0 Kudos
the_rock
Legend
Legend

I cant recall what default settings are now, but what guys said makes total sense, just create new one and enable those options.

Andy

0 Kudos
AkosBakos
Leader Leader
Leader

By the "offical' https service object, those settings are grayed out. Thats why I created a screenshot of a total new object.

And don't forget, if you make a change on a service object, it will affecten on every rule, where the object in in use. So be careful 🙂

Akos

----------------
\m/_(>_<)_\m/
0 Kudos
the_rock
Legend
Legend

Very true mate! Btw, it is possible to do on default service, just override the settings and option is there, but I agree, always better to create custom one in case like this.

Andy

0 Kudos
AkosBakos
Leader Leader
Leader

Exactly. A long long ago, I changed one default service object parameters... It wasn't the best deceison. 🙂

...live and learn...

Akos

----------------
\m/_(>_<)_\m/
(1)
the_rock
Legend
Legend

I think I know the reason mate...back then, you forgot to eat enough cabbage 😉

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events