- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Good evening.
At the moment, we need to provide a bypass to the resource https://website.com/ which, when connected to it, accesses the resource https://add.website.com/.
The https://add.websitedmz.com/ resource has a self-signed certificate.
Nevertheless, despite the bypass rules, this https://add.websitedmz.com/ resource is still detect, which interferes with the work of the entire https://websitedmz.com/ resource.
self-signed cert add.websitedmz.com was added to trusted ca but still detectable.
Please suggest how to bypass this resource.
Can you show bypass rule for it? Please blur out any sensitive info.
Andy
good morning
This is from test open server, on the production CP we hame the same issue, difference between them only in number of applications
As part of HTTPS Inspection, we also validate the certificate of the site you are accessing.
Have you added the self-signed certificate to the trusted CA list in SmartDashboard?
good morning
Have you added the self-signed certificate to the trusted CA list in SmartDashboard?
Yes, i did.
I'm referring to the certificate for add.websitedmz.com itself.
added with all CA, still don t work
Same Untrusted Ceertificate Issue:
Certificate DN: "O=websitedmz.com", Requested Server Name: add.websitedmz.com See sk159872
Please look into this thread: https://community.checkpoint.com/t5/Security-Gateways/HTTPS-Certificate-validation-SK159872/td-p/131...
No, this is not CA cert, this is the web server certificate. It clearly shows "Issued by Untrusted". You need the root cert, which is probably not applicable to self-signed. I suggest you add any third party certificate to that server, preferably issued by your own corporate CA or AD, and then add that signing CA as trusted root.
Thanks. Can I still make checkpoint ignore an issued by untrusted certificate and bypass it, beside making third party certificate? I m affraid it is not first case...
The log says "Detect", which means traffic is not affected. Why would you need an exception? To avoid logging?
I can t access the second domain level site https://websitedmz.com/. because some issues with https inspection on third domain level site https://add.websitedmz.com/. When i turn off the Https inspection, it works fine. Can t say why.
@_Val_ wrote:The log says "Detect", which means traffic is not affected.
Next step is Inspect.
Add a bypass for that level too. Also, in HTTPS Inspection / Server Validation , make sure you did not check box to drop traffic from with untrusted certs.
It is turned off.
Hello, I am unable to find this section, can you tell me how to get to it?
Its in legacy dashboard.
Hello, I can't find this settings section, can you tell me how to get to it?
You have to get to the legacy SmartDashboard, which you do by going here:
From there, click on HTTPS Validation
I would definitely double check option @_Val_ mentioned for untrusted cert (its in legacy https inspection dashboard settings)
Andy
i bet this is some sort of bug, because dashboard settings is off
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
19 | |
12 | |
8 | |
7 | |
7 | |
6 | |
6 | |
4 | |
4 | |
3 |
Wed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasMon 22 Sep 2025 @ 03:00 PM (CEST)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security EMEAWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasMon 22 Sep 2025 @ 03:00 PM (CEST)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY