- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Usercheck for External Users
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Usercheck for External Users
Hi,
What we have:
R80.40 JHF take_125
Application Control & URL Filtering
Https Inspection Enabled for Outbound traffic only
What we require:
Our organization would like to limit incoming traffic to a URL to only North America IP Addresses. I used Updatable Objects in Access Control/Application Layer to block non-North America addresses but I want to inform users via the Usercheck portal in case their ISP's have yet to update their ASN geographic locations.
What I have done:
-Under Gateway Cluster properties, I have enabled Usercheck
-Created an Alias in our internal DNS pointing to the Gateway cluster IP
-Specified "Through All Interfaces" in Portal Accessbility
Result:
The Application rule blocks the page and does get logged but the usercheck page does not come up. Is it possible to use Usercheck for external clients? If it is, can this be done without enabling https inspection for inbound traffic?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If the website in question is https, HTTPS Inspection is absolutely required for a UserCheck Redirect to work correctly.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi PhoneBoy,
Thank you for the confirmation. Is there a particular SK that this refers to? I just wanted CP documentation to back up my report.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The logic is similar to: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Basically, there is now way to inject the necessary redirect without doing HTTPS Inspection on the connection,
