- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Windows Server 2016 update services reporting "We couldn't connect to the update service. We'll try again later, or you can check now. If it still doesn't work, make sure you're connected to the Internet."
HTTPS cert from the R80.10 T_70 gateway was installed on the server and HTTPS sites were accessible with certificate substitution properly reported.
Option "Bypass HTTPS inspection of all traffic to all known software update services is checked.
Adding manual bypass rule for the source host's traffic in HTTPS Inspection rules did not help.
After spending an ungodly amount of time looking into Microsoft's side of things, I've decided to look into Checkpoint.
The findings are:
1. Windows Update fails through Security Gateway with enabled HTTPS Inspection
2. Specific HTTPS sites that use ECDHE ciphers are not accessible when HTTPS Inspection is enabled
With changes described in the above SKs made, still getting same error.
Implemented HTTPS Inspection Enhancements in R77.30 and above , Section:
Not really a good option, as:
Still experiencing errors.
Disabling HTTPS inspection on the gateway completely allows Windows Update to work.
Hi Vladimir,
You need to write bypass for the following sites for windows updates as a result of checking the https inspection i have done on checkpoint firewall.
nexus.officeapps.live.com
fe2.update.microsoft.com
delivery.mp.microsoft.com
vortex-win.data.microsoft.com
cp601-prod.do.dsp.mp.microsoft.com
geover-prod.do.dsp.mp.microsoft.com
big.telemetry.microsoft.com
Korkut
Thank you!
I am a bit surprised that these URLs are not updates automatically, as it states they should have:
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY