Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
xiro
Contributor

Page works only when HTTPS inspected

Hi, I just faced an strange issue, which hasn't ever occured in my 10 years of working with Check Point.

 

We have a server that needs to access Apple resources. Sometimes it worked, sometimes it didn't.

The ruleset for NW & AppC are fine, everything is allowed.

 

We then realized that user privileges in HTTPS inspection ruleset caused the strange behavior.

Per Default: The server was bypassed -> with a bypass, it doesn't work.

As soon as a user logged in, it triggered an AR, which caused the connection to be inspected - and then it works.

 

We tried to analyze this, and definitely the behavior is the opposite of the behavior you'd usually expect:

A bypass doesn't work, an inspect works.



My only logical explanation would be, that the cipher/protocol client-settings of the internal server are  not compatible with Apple - and that an "inspect" masks these settings to the outbound GW ciphers - and therefore "fixes" the connection.

But - the server is up-to-date, has proper settings, supports TLS1.2 & 1.3 with secure ciphers & everyhting else worked, except this one service.

 

Has anyone ever faced something like that or has an idea what could cause such a behavior?

0 Kudos
3 Replies
G_W_Albrecht
Legend
Legend

I would suggest to contact CP TAC to get the reason for this!

 

CCSE CCTE CCSM SMB Specialist
0 Kudos
the_rock
Legend
Legend

I had never heard of something like that myself. It usually works when site is bypassed in https inspection policy, not the other way around. Can you send some screenshots of how this is configured when it works? Just blur out any sensitive data.

Andy

0 Kudos
PhoneBoy
Admin
Admin

You can prove this is exactly what happens by taking a tcpdump in both situations (with and without HTTPS Inspection enabled for this server).
You should see the cipher suites and such used.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events