Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ramiro_gallegos
Participant

R82.00.11 Inbound ssl inspection

Hi everyone,

Could someone clarify how Inbound SSL Inspection is handled in R82.00.11 Embedded?

We have a Spark 2560 managed locally. We are working with R82,00.11 and while setting up a server service, we noticed the option to enable Inbound SSL Inspection.

In previous version releases, this feature required centralized management (Smart-1) and couldn't be configured locally.

If I check this box on R82.00.11, can Inbound SSL Inspection now be fully configured and used via Local Management, or does it still rely on Smart-1 Centralized Management?

Thanks for your help!

 

Ramiro

0 Kudos
3 Replies
Chris_Atkinson
MVP Diamond CHKP MVP Diamond CHKP
MVP Diamond CHKP

The relevant section of the Locally managed admin guide is available here: Configuring Servers

CCSM R77/R80/ELITE
0 Kudos
Itay_David
Employee
Employee

Hi,

Yes — starting with R82.00.11, Inbound SSL Inspection is supported on locally managed Spark firewalls, including the Spark 2560.

So if you see the Inbound SSL Inspection option while configuring the server object, you can configure and use the feature directly through Local Management — Smart-1 Centralized Management is not required.

For the configuration, HTTPS Inspection should be enabled on the gateway, and when enabling Inbound SSL Inspection for the server, you will need to upload the server's P12 certificate (including the private key) and provide its password.

The gateway can then decrypt incoming HTTPS traffic destined for the protected server, inspect it with the relevant security blades / Threat Prevention protections, and re-encrypt it before forwarding it to the internal server.

I would also really appreciate your feedback once you manage to configure and use the feature in your environment. Please let me know how it works for you and if you encounter any issues.

0 Kudos
ramiro_gallegos
Participant

Hi

Thank you for your response, although I'm a little confused because I submitted a ticket to TAC and they told me that it doesn't work locally.

They said: "Yes, Ramiro, you will be able to see the option to setup the feature, but it will not work in a locally managed environment. It is only supported on centrally managed environments. Hope this clears it up for you, thank you and take care." (SR#6-0004727584 r82.00.11 known limitations)

So before to configure this feature or pruchase the central managment my question is: Does it work locally or not?? 

 

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events