- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone,
In our network environment, we have two firewalls. We attempted to enable SSL inspection on both firewalls, but encountered an error message: “HTTP parsing error.” Notably, both firewalls utilize the same self-signed certificate for outbound inspection. Surprisingly, when we enable HTTPS inspection on only one of the firewalls, everything functions correctly.
Checkpoint firewall is second device in architecture.
the issue is happened on different sites, for example ssllabs.com, apple.com.
some sites work correctly for example udemy.com with inspection enabled.
What steps should we take to troubleshoot this issue?
Thank you
On the problematic firewall could you check if you can access the internet from this gateway?
https://support.checkpoint.com/results/sk/sk108202
Check:
Also I am not sure if 2 Check Point firewalls in the same traffic flow is good with both HTTPS inspection.
Documentation states: HTTPS Inspection can be enabled on a single Security Gateway at first, and then expanded to additional Security Gateways.
Does not mention if they can be inline, so worth checking. Maybe someone else knows that here.
Hey,
The first fw is not Checkpoint
If I activate ssl decryption on one of them everything works fine, the problems start when on both of them try to opens tls traffic.
All Firewalls have access to the internet
Sorry, no offense meant - but i just read your issue to my tech support collegues and we had a big laugh together 🤣
It is no wonder that this does not work; and what could be achieved by 2 times SSL inspection ? I would suggest to enable SSL inspection on CP GW only.
Firewall vendors may employ a variety of for detecting threats within encrypted traffic, such as signature-based detection, behavior analysis, machine learning algorithms, heuristics, anomaly detection, or sandboxing. Each technique has its strengths and weaknesses, and vendors may prioritize different approaches based on their research, development, and expertise
This is in addition to the constraints that exist in the organization due to a complex topology
In addition, I don't see any problem with ssl decryption by different vendorim, in other environment there are both firewalls, and proxy's, and products for ssl visabilty, which decrypt tls one after the other without any problem.
Double https inspection makes certificate management complex. It is done via MITM and client needs to trust the certificate from gateway. In this case 2. In this case the first firewall will be the client from Check Point point of view. Due that the first gateway sets up the connection on it's own (if inspected).
client <-> first firewall (MITM HTTPS inspection) <-> Check Point (MITM HTTPS inspection) <-> Web server
The Check Point will be inspecting traffic initiated from the first firewall. The first firewall starts the traffic because it is doing MITM for the client. I am getting headache only thinking about this scenario.
Can you give a sketch of the network topology ?
Hey,
In this scenario, client access to the internet through two firewalls. The first one is a LAN firewall (not Checkpoint) that performs LAN segmentation and forwards traffic to the second firewall, which is a WAN firewall that perfom a accses to internet (Checkpoint).
Thank you
Ah first fw is not Check Point that changes is. It still can be config error. Start with the SK's below:
https://support.checkpoint.com/results/sk/sk108202
https://support.checkpoint.com/results/sk/sk65123
https://support.checkpoint.com/results/sk/sk64521
https://support.checkpoint.com/results/sk/sk112214
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 18 | |
| 12 | |
| 8 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY