Hello, we have recently migrated to Checkpoint for our firewall and we are having many issues with HTTPS inspection.
Here is our setup:
We want to inspect packets going to docs.google.com or sites.google.com so that we can block specific URLs and Google sites from the student network and we do not decrypt any other sites. The problem we have is that when we try to enroll a new chromebook, it needs to connect to either tools.google.com, clients1.google.com, clients2.google.com, clients3.google.com or clients4.google.com and these packets are being decrypted even though there is no rule in our firewall telling it to decrypt. Attached to this post is a screenshot of what the logs show and I highlighted that the device is going to clients2.google.com. The destination shows docs.google.com which would explain why it was decrypted as we decrypt this subdomain, but the device was not going to that subdomain so this rule should NOT have applied.
Has anyone else experienced this? My guess here is that perhaps there is some reverse lookup that is being done on the destination that is causing this problem. We just migrated from Palo Alto Networks firewall and we were not having this problem.
Any help will be greatly appreciated.