> Source: [sk101166](https://support.checkpoint.com/results/sk/sk101166)

# sk101166 - HTTPS Inspection ignores HTTPS traffic via proxy with authentication

| Property | Value |
|----------|-------|
| Solution ID | sk101166 |
| Date Created | 2014-06-07 |
| Last Modified | 2021-07-21 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * HTTPS traffic via proxy with NTLM authentication is not inspected by HTTPS Inspection and is bypassed.
* HTTPS traffic via proxy with Kerberos authentication is not inspected by HTTPS Inspection and is bypassed.

## Cause

This is an HTTPS Inspection limitation.

In case of proxy with NTLM Authentication, the reply to Security Gateway's "connect" request is "407 Proxy Authentication Required", so Security Gateway short-circuits the connection. As a result, HTTPS Inspection is not enforced.

## Solution

The behavior of Security Gateway / Cluster can be controlled by the value of kernel parameter ***ws_block_non_compliant_connect_response***:

|-------------------------------------------|-----------------------------------------------------------------------------------------------|
| ws_block_non_compliant_connect_response=0 | Default. HTTPS traffic via proxy with NTLM authentication is *not* inspected and is bypassed. |
| ws_block_non_compliant_connect_response=1 | SSL connections to proxy with NTLM authentication are dropped.                                |

* Show / Hide instructions for R77.20 and above   

  * To check the current value of this kernel parameter:

    ***\[Expert@HostName\]# fw ctl get int ws_block_non_compliant_connect_response***   

  * To configure Security Gateway *on-the-fly* (does not survive reboot) to drop SSL connections to proxy with NTLM authentication:

    ***\[Expert@HostName\]# fw ctl set int ws_block_non_compliant_connect_response 1***   

  * To configure Security Gateway *permanently* (survives reboot) to drop SSL connections to proxy with NTLM authentication:

    Follow [sk26202 - Changing the kernel global parameters for Check Point Security Gateway](http://supportcontent.checkpoint.com/solutions?id=sk26202).
    1. Create the *$FWDIR/boot/modules/fwkern.conf* file (if it does not already exit):

       ***\[Expert@HostName\]# touch $FWDIR/boot/modules/fwkern.conf***   

    2. Edit the *$FWDIR/boot/modules/fwkern.conf* file in Vi editor:

       ***\[Expert@HostName\]# vi $FWDIR/boot/modules/fwkern.conf***   

    3. Add the following line (spaces are not allowed):

       ***ws_block_non_compliant_connect_response=1***   

    4. Save the changes and exit from Vi editor.   

    5. Check the contents of the *$FWDIR/boot/modules/fwkern.conf* file:

       ***\[Expert@HostName\]# cat $FWDIR/boot/modules/fwkern.conf***   

    6. Reboot the Security Gateway.   

    7. Verify that the new value was set:

       ***\[Expert@HostName\]# fw ctl get int ws_block_non_compliant_connect_response***

  <br />

* Show / Hide instructions for R77.10 and lower   

  1. [Contact Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) to get a Hotfix for this issue.  
     A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
     For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.   

  2. Hotfix has to be installed on ***Security Gateway / each cluster member***.

     **Note:** In cluster environment, this procedure must be performed on *all* members of the cluster.   

  3. Transfer the hotfix package to the machine (into some directory, e.g., */some_path_to_fix/* ).   

  4. Unpack the hotfix package:

     ***\[Expert@HostName\]# cd /some_path_to_fix/***   
     ***\[Expert@HostName\]# tar -zxvf fw1_wrapper_\<HOTFIX_NAME\>.tgz***   

  5. Install the hotfix:

     ***\[Expert@HostName\]# ./fw1_wrapper_\<HOTFIX_NAME\>***
     **Note:** The script will stop all of Check Point services (*cpstop* ) - read the output on the screen.   

  6. Do NOT reboot the machine yet.   

  7. To configure Security Gateway *permanently* (survives reboot) to drop SSL connections to proxy with NTLM authentication:

     Follow [sk26202 - Changing the kernel global parameters for Check Point Security Gateway](http://supportcontent.checkpoint.com/solutions?id=sk26202).
     1. Create the *$FWDIR/boot/modules/fwkern.conf* file (if it does not already exit):

        ***\[Expert@HostName\]# touch $FWDIR/boot/modules/fwkern.conf***   

     2. Edit the *$FWDIR/boot/modules/fwkern.conf* file in Vi editor:

        ***\[Expert@HostName\]# vi $FWDIR/boot/modules/fwkern.conf***   

     3. Add the following line (spaces are not allowed):

        ***ws_block_non_compliant_connect_response=1***   

     4. Save the changes and exit from Vi editor.   

     5. Check the contents of the *$FWDIR/boot/modules/fwkern.conf* file:

        ***\[Expert@HostName\]# cat $FWDIR/boot/modules/fwkern.conf***

     <br />

     <br />

  8. Reboot the machine.   

  9. Verify that the new value was set:

     ***\[Expert@HostName\]# fw ctl get int ws_block_non_compliant_connect_response***

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
