> Source: [sk108262](https://support.checkpoint.com/results/sk/sk108262)

# sk108262 - HTTPS Categorization or Inspection does not work on Virtual Systems which do not have direct DNS connectivity

| Property | Value |
|----------|-------|
| Solution ID | sk108262 |
| Date Created | 2015-10-19 |
| Last Modified | 2024-10-24 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * HTTPS Categorization does not work on Virtual Systems which do not have direct DNS connectivity (even if there is DNS connectivity for VS0)
* CRL/OCSP fetch fails for wstlsd when the VS does not have connectivity to a DNS server
* If proxy is used in Global Properties or in the VS object in SmartConsole and the proxy is defined with FQDN wstlsd fails to resolve the proxy IP when the VS does not have connectivity to a DNS server. (or resolves to the wrong IP address in cases where DNS-per-VS is used)

## Cause

By design, the *wstlsd* process, which is responsible for HTTPS Categorization, must have direct connectivity from the VS to a DNS server.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
