Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
GDell_CP
Participant

Usercheck for External Users

Hi,

What we have:

R80.40 JHF take_125

Application Control & URL Filtering

Https Inspection Enabled for Outbound traffic only

What we require:

Our organization would like to limit incoming traffic to a URL to only North America IP Addresses. I used Updatable Objects in Access Control/Application Layer to block non-North America addresses but I want to inform users via the Usercheck portal in case their ISP's have yet to update their ASN geographic locations.

What I have done:

-Under Gateway Cluster properties, I have enabled Usercheck

-Created an Alias in our internal DNS pointing to the Gateway cluster IP

-Specified "Through All Interfaces" in Portal Accessbility

Result:

The Application rule blocks the page and does get logged but the usercheck page does not come up. Is it possible to use Usercheck for external clients? If it is, can this be done without enabling https inspection for inbound traffic?

 

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

If the website in question is https, HTTPS Inspection is absolutely required for a UserCheck Redirect to work correctly.

0 Kudos
GDell_CP
Participant

Hi PhoneBoy,

 

Thank you for the confirmation. Is there a particular SK that this refers to? I just wanted CP documentation to back up my report.

 

0 Kudos
PhoneBoy
Admin
Admin

The logic is similar to: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Basically, there is now way to inject the necessary redirect without doing HTTPS Inspection on the connection,