- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi
On my lab I am trying to use usercheck alongside with HTTPS inspection:
Rule 11.2
When trying to connect to Cnn.com a notification comes up and everything is fine and work as expected.
When try to connect to Youtube or facebook i get "this site can't be reached"
when checking the logs i see that youtube and facebook are rejected for a reason that i don't know:
I don't know why rule 11.2 is rejecting youtube and facebook when the action is inform and cnn is working!
this is how HTTPS inspection is configured:
Your browser (probably Chrome) has pinned HTTPS certificates for popular sites such as facebook and definitely youtube which is a google-owed site. In these cases the browser itself will block the display of the UserCheck as a man-in-the-middle attack, which it most certainly is. Try a few different browsers.
What is the purpose of Userchek then, if Chrome (which is the most used browser) will block it?
Chrome will only block UserChecks for sites whose certificates are pinned in the browser, which will always include google-owned sites (youtube, google.com, etc) and key major sites like fakebook. Chrome is sensing what it perceives to be a man in the middle attack and blocking it, and there is no way to disable this that I know of.
The purpose of UserChecks is attempting to notify the user that their connection was blocked (it is not a connectivity/DNS problem), and provide a reference number they can use when trying to find the specific block event in the logs. However there are a variety of technical situations where a UserCheck cannot be sent to the user, or it is sent but the user cannot see it. You have run into one of those situations. Another example: any blocks/drops by the IPS blade will never send a UserCheck as IPS does not support that feature at all.
Make sure user check is enabled for all interfaces under gateway object properties (portal -> user check) and test. if same issue, try maybe resetting Chroms browser and see if same happens.
Happy New Year.
Best,
Andy
The issue in your policy is that Facebook and YouTube is not HTTPS inspected but bypassed as shown in your screenshot. This is because you use the "HTTPS services - bypass" object where Facebook is included (and bypassed). You can find all domains etc. in this SK HTTPS Inspection bypass list object (checkpoint.com)
And if your gateway doesn't inspect the traffic it can't display the UserCheck page and simply rejects the connection which is to be expected.
Thats an excellent point, did not see that from the screenshots the first time.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 20 | |
| 16 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY