Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
henryck
Participant

Domain objects in R80.40 https inspection policy

I am looking for a solution to applying inbound https inspection to web application proxies that secure external facing web servers with different certificates. I cannot find any SKs to indicate whether its supported to use domain objects (fqdn) or similar.

The issue we face is multiple sites are configured on the same proxy that then use different certificates. We NAT from a single public IP in our block, however when creating the https inspection policy using a network object this presents the configured certificate to clients, which in our case does not solve the issue.

In lieu of having to assign multiple IPs from our block to different sites, can anyone advise if they have faced similar issues and have found a solution?

Thanks! 

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

Not with domain objects, but with Custom Application/Site objects.
See: https://community.checkpoint.com/t5/Next-Generation-Firewall/Is-there-SNI-support-for-inbound-HTTPS-... 

henryck
Participant

Thanks, I'll give that a go. Is there any available SKs or documentation that get into this a bit more?

0 Kudos
PhoneBoy
Admin
Admin

The information in that thread came from R&D, as I recall, so it should be fairly accurate.
If you're having issues, let us know.

0 Kudos
henryck
Participant

Support confirmed bug in r80.40, to be patched in an upcoming JHF.

PRJ-9661,
PRHF-8304

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

0 Kudos