> Source: [sk121214](https://support.checkpoint.com/results/sk/sk121214)

# sk121214 - HTTPS Inspection on Locally Managed Spark Firewall

| Property | Value |
|----------|-------|
| Solution ID | sk121214 |
| Date Created | 2017-10-31 |
| Last Modified | 2024-12-26 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |

## Solution

**Table of Contents**

* Introduction
* Ports
* Bypass Policy
* Exceptions
* Deployment
* Troubleshooting
* Known Limitations
* Related solutions

Introduction {#Introduction}
----------------------------

This article outlines some recommendations and best practices for easy HTTPS Inspection deployment and use in locally managed SMB appliances.

HTTPS inspection is supported in Locally Managed Quantum Spark appliances that run the firmware R77.20.70 and higher.

To enable SSL inspection on your Quantum Spark Gateway, in WebUI go to **Access Policy** -\> **SSL Inspection** page, and choose one of these options:

* **SSL traffic inspection**   

  Allow different Software Blades that support SSL Inspection to inspect traffic that is encrypted by the Secure Sockets Layer (SSL) protocol. To allow the Quantum Spark Gateway to inspect the secured connections, all hosts behind the Quantum Spark Gateway must install the Quantum Spark Gateway's CA certificate.  

  Software Blades that support SSL traffic inspection:   

  * Application Control and URL Filtering
  * IPS
  * Anti-Virus
  * Anti-Bot
  * Threat Emulation
* **HTTPS categorization (Default)**   

  HTTPS categorization allows filtering specified HTTPS URLs and applications without activating SSL traffic inspection.

Ports {#Ports}
--------------

When SSL traffic inspection is configured, Quantum Spark Gateway performs an inspection on outbound traffic over HTTPS protocol. Default ports for HTTPS Inspection:

* 443
* 8080 (proxy)
* 3128

To add additional ports for HTTPS inspection, go to ***Users \& Objects*** -\>***Services*** -\> ***HTTPS service settings*** or find the parameter ***Additional HTTPS ports*** in the ***Device*** -\> ***Advanced Settings*** page for additional proxy ports.

Bypass Policy {#Bypass Policy}
------------------------------

An administrator may want to bypass certain categories or networks from SSL traffic inspection based on the following considerations. The common ones are presented in the policy page to simplify configuration.

* **Regulation / Privacy** - Some countries may forbid SSL inspection for categories such as Finance, Government and Health. There may be privacy and legal regulations on the use of this feature depending on the country in which you are located. Review your local laws and regulations.  

* **Deployment** - A Host that did not install the Gateway's CA as trusted might experience connectivity issues. This might be a common scenario with hosts behind a guest wireless network for example, which is why those are bypassed by default.  
  **Note** : only a network assigned to ***Separate network*** will be bypassed.   

* **Performance** - You can bypass categories like streaming to reduce performance impact.  

* **Well known update services** - The gateway includes build-in well-known update services that are considered safe. The default policy is to bypass traffic to those services.

Bypass policy can be based on categories and custom applications. It is not possible to base bypass policy and exceptions on specific built-in applications (from Application \& URL filtering service updates).   
To add additional categories to bypass due to various considerations like the ones mentioned above, select the desired categories in ***Bypass other categories and sites*** in the Policy page.   
To configure a manual exception to bypass a specific source/destination/port, add an exception in the ***Exceptions*** page.   

**Note** : when using custom applications in bypass policy (and exceptions) the URLs used to define the application should be based on information from the certificate, which is not always consistent with the URL used to reach the website in the browser. Refer to [sk113935](https://support.checkpoint.com/results/sk/sk113935) for more details.   
The same applies for custom applications used in access policy rules when HTTPs categorization is configured instead of SSL traffic inspection.

Exceptions {#Exceptions}
------------------------

Manual exceptions can be configured if there is a need to bypass a specific source/destination/service from SSL traffic inspection (for bypass of categories or specific custom application, use ***Bypass other categories and site***s mentioned above).

When configuring manual exceptions service should be set to a specific custom service or "HTTPS" and not to "Any" to avoid additional performance impact (of performing SSL inspection related operations on all ports).

**Note**: certificate warning may appear even for traffic that was configured to be bypassed if you have a manual exception for category in the Exceptions page

Deployment {#Deployment}
------------------------

To avoid connectivity issues and warnings on inspected connections, all hosts behind the gateway must install the Quantum Spark Gateway's CA certificate.

Certificate installation varies according to the OS. To learn how to install the certificate in your machine, see your OS vendor instructions.

In Windows OS:

1. Download the CA certificate from the Quantum Spark Gateway's WebUI and install it manually in every host.
2. Click the file and follow the Wizard instructions to add the certificate to the Trusted Root Certification Authorities repository. (This is not the default repository in the Certificate Import Wizard.)   
   To distribute the certificate to a large group of users, use GPO or group policy.

Installing CA on mobile phones might not apply to some of the installed applications that use their own trusted CAs repository. In such a case, you must add a bypass exception to avoid connectivity issue.

SSL Inspection uses the existing internal CA by default. To use your own certificate, you must replace the internal CA.  

To replace the internal CA:

1. In Quantum Spark Gateway's WebUI, go to **Device** -\> **Certificates** -\> **Internal Certificate**.
2. Click the "Replace Internal CA" button to upload a CA certificate file that includes the private key to be used by the gateway to sign certificates with the uploaded CA.
3. Enter the private key password that was used when the CA was created.

Troubleshooting {#Troubleshooting}
----------------------------------

To check if SSL traffic is inspected or bypassed, it is advised to examine these checkboxes:

* **Enable inspect logs**
* **Enable bypass logs**

**Note**: By default, these checkboxes are cleared (disabled) to avoid excessive logs. They are usually not needed and should only be used when troubleshooting SSL Inspection related issues since allow/block logs will be generated by the relevant blades for SSL traffic regardless of this configuration.

Known Limitations {#Known Limitations}
--------------------------------------

|----------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID       | Symptoms                                                                                                                                                                                 |
| SMB-3254 | SSL Inspection is not performed if a category-based exception/bypass is used when the URL Filtering blade is disabled. Note: Category-based exceptions/bypass are configured by default. |

Related Solutions {#Related solutions}
--------------------------------------

**Configuration**

* [sk108202 - Best Practices - HTTPS Inspection](https://support.checkpoint.com/results/sk/sk108202)
* [sk65123 - HTTPS Inspection FAQ](https://support.checkpoint.com/results/sk/sk65123)
* [sk108654 - How to control support for SSLv2 handshake in HTTPS Inspection](https://support.checkpoint.com/results/sk/sk108654)
* [sk90840 - HTTPS Inspection is not supported for IPv6 traffic](https://support.checkpoint.com/results/sk/sk90840)
* [sk89960 - 'HTTPS Validation detected a connection attempt from client CLIENT@DOMAIN that has not installed CA certificate today' log in SmartView Tracker for first connection attempt over HTTPS to an update service](https://support.checkpoint.com/results/sk/sk89960)

**Troubleshooting**

* [sk115145 - Threat Emulation is not passing HTTPS traffic to emulation without enabling HTTPS inspection](https://support.checkpoint.com/results/sk/sk115145)
* [sk111754 - HTTPS traffic to Google services from Chrome cannot be inspected by HTTPS inspection rules](https://support.checkpoint.com/results/sk/sk111754)
* [sk113935 - Bypass/Inspect rule by Category in HTTPS Inspection policy works for some sites but not others](https://support.checkpoint.com/results/sk/sk113935)
* [sk104238 - Dropbox client does not work if HTTPS Inspection is enabled](https://support.checkpoint.com/results/sk/sk104238)
* [sk114419 - Unable to bypass Skype in HTTPS Inspection policy using a "Category", or a custom "Application/Site" in the rule](https://support.checkpoint.com/results/sk/sk114419)
* [sk108191 - Login failures for Apple Devices when HTTPS inspection is enabled on the Security Gateway](https://support.checkpoint.com/results/sk/sk108191)
* [sk112214 - Several HTTPS web sites and applications might not work properly when HTTPS Inspection is enabled on Security Gateway](https://support.checkpoint.com/results/sk/sk112214)

**Note**: Some guidelines in the related solutions may be different for Locally Managed Quantum Spark Gateways.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
