- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hi team.
I'm trying to add https inspection bypass rules with custom site category with full URL or regex in this category.
But it doesn't work and Check Point inspects this traffic.
Any ideas how to make it work?
A bit more information would be helpful (Version you are using, the url you want to bypass, your regex etc.).
Usually, when URL and regex definitions don't work to bypass HTTPS websites, you'll be required to bypass the IP address of the website.
Follow these steps:
Related SKs: sk108762, sk122158, sk114160, sk114419, sk113935,sk132913
Hi Danny.
Thank's but I know about bypass by destination IP.
This method is too time-consuming because web sites has multiple IP addresses. So I need to bypass inspection with wildcard in URL, for example *.site.com
Which website would you like to bypass?
For example vtb.ru with all subdomains
vtb.ru owns just a single /24 network: 193.164.146.0/24
So if you create a network object to reflect vtb.ru's network and bypass it within your HTTPS Inspection policy you should be all good.
Thank you
The 'Thank you' badge can be found right below the Actions link. 
Hi @Danny
How did you find out that vtb.ru owns that single /24 network?
I have the same problem where the sites are inspected even though I have a custom bypass application with a list of URLs using regex. The URLs still get inspected and break my connection.
My requirement is to bypass the following.
*.oms.opinsights.azure.com
*.blob.core.windows.net
*.azure-automation.net
*.ods.opinsights.azure.com
winatp-gw-cus.microsoft.com
winatp-gw-eus.microsoft.com
winatp-gw-neu.microsoft.com
crl.microsoft.com
ctldl.windowsupdate.com
events.data.microsoft.com
uk.vortex-win.data.microsoft.com
uk-v20.events.data.microsoft.com
winatp-gw-uks.microsoft.com
winatp-gw-ukw.microsoft.com
What are my options as currently, I can't give my organisation a working solution?
Does anyone have any ideas on how to resolve the above issues?
Enable module probe bypass (sk104717)
Run: fw ctl set int bypass_on_enhanced_ssl_inspection 1 In $FWDIR/modules/fwkern.conf, add this line: bypass_on_enhanced_ssl_inspection=1
Hi Alessandro,
Was this in response to my issue? If it was, I've been there and felt the pain of enabling probe bypass.
I'm still waiting for CP to supply me with the SNI fix to supplement enabling probe bypass but this hasn't happened as yet.
yes, was....
what is your take on r80.10 ?
It's ever-changing. Currently 169.
No, the list above is from Microsoft. I'd created an application using the proper Regex format.
I have two clusters with r80.10 take 142, probe bypass on and my regex like this (^|.*\.)*microsoft\.com
working fine...
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 1 | |
| 1 | |
| 1 | 
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY