> Source: [sk110237](https://support.checkpoint.com/results/sk/sk110237)

# sk110237 - HTTPS Inspection not inspecting traffic to internal web server

| Property | Value |
|----------|-------|
| Solution ID | sk110237 |
| Date Created | 2016-02-23 |
| Last Modified | 2022-07-18 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- Inbound HTTPS traffic to static NATed web server is not being inspected by HTTPS Inspection.

## Cause

HTTPS Inspection policy has the host object that is automatically static NATed in the destination column.

HTTPS Inspection does not recognize the NAT IP address of the object in the HTTPS Inspection rulebase.  

HTTPs inspection rule has destination set configured as the real IP of the the server instead of NAT IP  

None of the Security blades are enabled (Such as IPS, APPI,URLF)  

**Note: The issue could happen if security blades are disabled or with rules configured as described above**

## Solution

1. Ensure that a security blade is enabled. For example, enable IPS which has HTTP-based protections enabled by default, or enable APPI or URLF and use one of their objects in the Access Control policy.
2. Create a host object representing the NAT IP address of the web server.
3. Add this newly created host object to the Destination column of the HTTPS Inspection rulebase.
4. Install Policy.
5. Verify that Inbound HTTPS Inspection is taking place via Smartview Tracker/ SmartLog.

**Or**

[Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) to get a Hotfix for this issue.   
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.  

**Note: Security blade has to be enabled with or without the hotfix.**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
