Hello experts.
We are investigating unusual outbound traffic on one of our customers with CP Gateways R80.30 Build 215 (Take 227).
We established HTTPS inspection of outbound traffic. Configured Access rules and HTTPSi policy for inspection of specific set of hosts source and destinations.
In logs we can observe usual staff for L4 like src IP, src User (from Identity Awareness), dst IP, dst FQDN (resource from HTTPi), etc.
Now we need to understand what kind of queries and HTTP requests (GET/POST) were sent in those sessions.
Dear community members,
could you please tell me how to log/monitor L7 queries with Check Point (like on WAF/LB for Web Inspection)?
Before asking I’ve searched for this topic on the Check Mates and didn’t find anything suitable. Is it possible after all to do it with CP Gateway?
Thank you in advance.