When i say “it doesn’t work” i mean it doesn't Inspect the traffic going from User to Proxy. I think it is Bypassed, but i didn't see it in the Smart Log. Also i check this traffic with fw ctl zdebug + drop, the traffic was not dropped.
Simple Network diagram
IP addresses was changed.
Simple Network Diagram.JPG in attached
Version of Checkpoint GW
Checkpoint Appliance 15600
GAIA OS R80.30
JHF 228
Details
So, desire of Security Team in my company is view the unecrypted traffic going from User to Internet for prevent Threats and viruses with Anti-Virus Blade and use the Application Control Blade to the fullest. But, position of our Security Team is using Proxy server for Internet access. At first, i created HTTPS rules for Proxy like:
HTTPS Inspection from Proxy to Internet.JPG in attached
And this rules works fine. Proxy traffic will Inspected, but i faced with 2 problems:
- I didn't see wich user get some viruses, because i see only IP address of Proxy Server
- This Proxy server used by other clients, like Linux users and Developers, whose software is not support HTTPS Inspection and i cannot bypassed it.
After that i created another HTTPS rules like:
HTTPS Inspection from User to Proxy.JPG in attached
Where Pent_Windows is host with IP 10.10.10.10
But this rule is not working, i mean the traffic is not Inspected. Also i coudn't see Bypass in Smart Log.
My question is, how can i make the rule work when i Inspect the traffic going from User to Proxy?
In our company we use tcp/80 and tcp/3128 for Proxy.
Thank you in advance.
TGS