> Source: [sk111754](https://support.checkpoint.com/results/sk/sk111754)

# sk111754 - HTTPS Inspection cannot inspect HTTPS traffic from Google Chrome web browser to web servers over QUIC 

| Property | Value |
|----------|-------|
| Solution ID | sk111754 |
| Date Created | 2016-06-09 |
| Last Modified | 2025-12-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * When accessing websites such as Gmail or BBC that support QUIC using a Chromium-based web browser (for example, Google Chrome or Microsoft Edge), the browser shows the web server's certificate (click the padlock icon in the address bar) instead of the HTTPS Inspection certificate deployed on the Security Gateway.

* When accessing the same web servers in other web browsers that are not Chromium-based, the web browser shows the deployed HTTPS Inspection certificate as expected (click the padlock icon in the address bar).

* When viewing a web page in the Google Chrome web browser, the Web Developer Tools \> "**Security** " tab shows the "**QUIC** " protocol in the "**Secure Connection**" section.

  Example:


  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111754/11709250642.PNG)
* SmartConsole / SmartView shows this security log the Security Gateway with HTTPS Inspection enabled:

  Section "Log Info":  

  Blade: HTTPS Inspection  

  Type: Connection  

  Section "HTTPS Inspection":  

  HTTPS Inspection Action: Inspect  

  Section "Traffic":  

  Service: quic (UDP/443)  

  IP Protocol: UDP (17)  

  Destination Port: 443  

  Section "Policy":  

  Action: HTTPS Inspect

## Cause

This explanation applies to Security Gateway R82 and higher:
> When HTTPS Inspection is enabled, the Check Point Security Gateway establishes two TLS connections and functions as a Man-in-the-Middle:
>
> (TLS Client) \<==\> (Check Point Gateway) \<==\> (TLS Server)
>
> * **Towards the TLS client**, the Security Gateway presents itself as the TLS server and presents a certificate signed by the Outbound CA of HTTPS Inspection.
> * **Towards the original TLS server**, the Security Gateway acts as the TLS client.
>
> Web browsers based on the Chromium engine, such as Google Chrome and Microsoft Edge, use a predefined trusted CA store (the Chromium Root Store) to establish HTTP/3 (QUIC) connections.
>
> For HTTPS Inspection to function properly, its outbound CA certificate needs to be deployed to the web browser.
>
> However, this is not possible for QUIC connections in Chromium-based web browsers, because they do not allow users to add custom CA certificates directly to the trusted CA store.
>
> Consequently, if the Check Point Security Gateway presents a certificate not issued by a trusted CA, the Chromium-based web browser terminates the connection during the handshake with an error indicating an untrusted certificate. In such cases, the web browser usually falls back to HTTP/2 TLS or an earlier protocol version (this behavior is outside of Check Point's control, as outlined in [RFC 9000](https://www.rfc-editor.org/rfc/rfc9000.html#name-overview) and [RFC 9001](https://www.rfc-editor.org/rfc/rfc9001.html#name-introduction)).
>
> For TLS traffic over TCP, Chromium-based web browsers behave differently, allowing users to import custom CA certificates into the web browser's trusted CA store to establish a trusted connection.
>
> When HTTPS Inspection is configured to inspect QUIC traffic, the Check Point Security Gateway generates a Security Log entry with the message "*HTTPS Inspection Action: Inspect*" to indicate the decision to intercept the traffic. This log is sent when the traffic matches the HTTPS Inspection rule on the Security Gateway. However, the QUIC traffic is not inspected because the Chromium-based web browser terminates the connection due to an untrusted certificate. The Chromium-based web browser typically falls back to HTTP/2 TLS or an earlier protocol version. Subsequently, HTTPS Inspection intercepts the connection, decrypts it, and allows inspection by the enabled Software Blades.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
