> Source: [sk163515](https://support.checkpoint.com/results/sk/sk163515)

# sk163515 - Websites using TLS 1.3 are not categorized correctly using "Categorize HTTPS Sites" feature in R80.20 and lower

| Property | Value |
|----------|-------|
| Solution ID | sk163515 |
| Date Created | 2019-11-17 |
| Last Modified | 2024-07-07 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Application Control \& URL Filtering policy is not enforced for specific websites when "Categorize HTTPS websites" feature is enabled and HTTPS Inspection feature is disabled, or the traffic is bypassed from HTTPS Inspection in versions below R80.20.  

* When checking Developer Tools (F12 key) on the browser or collecting a traffic capture of the communication, we can see that TLSv1.3 is used.  

* When reviewing the log, the IP address of the website is shown as the **resource** , while the category for this traffic is "Uncategorized".  

* Disabling TLSv1.3 on the browser side resolves the issue.

## Cause

* The "Categorize HTTPS Sites" feature does not support TLS 1.3 traffic when working with Security Gateways R80.20 and lower / Qantum Spark R80.20.x and lower.
* Later versions support categorizing of websites accessed with TLS 1.3 traffic - see more details below in the "Solution" section.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk144293)
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 118
* [Quantum Spark R81.10.00](https://support.checkpoint.com/results/sk/sk179004)

Check Point recommends to always upgrade to the most recent version ([Security Gateway](https://support.checkpoint.com/product/73) / [VSX](https://support.checkpoint.com/product/359) / [Security Management Server](https://support.checkpoint.com/product/184) / [Multi-Domain Security Management Server](https://support.checkpoint.com/product/166) / [SmartConsole](https://support.checkpoint.com/product/191)).

**Notes:**

* Starting from the versions specified above, the "Categorize HTTPS Sites" feature uses the Server Name Indications (SNI) to categorize TLS 1.3 when HTTPS Inspection is not inspecting the traffic.  
  This is the best effort behavior. Administrator can disable it.
* The "Categorize HTTPS Sites" feature does not validate SNI against the encrypted certificate
* There still might be issues categorizing the TLS 1.3 traffic. For example, when the SNI is empty.

<br />

**These workarounds are available (use one of them) for versions R80.20 and lower:**

* Enable and configure HTTPS Inspection.

  **Important** - In such case, Security Gateway / Cluster downgrades the TLS protocol version to one that it supports.

  See the [Security Gateway Administration Guide](https://support.checkpoint.com/product/73) for your version.
* Disable TLS 1.3 in a web browser on the clients.

  See the vendor documentation for your web browser.
* Configure a Clean Up rule in the Access Control policy to block the whole "Uncategorized" category:

  |---------|-------------|---------|--------------------------|--------|--------------------|--------------------|
  | Source  | Destination | VPN     | Services \& Applications | Action | Track              | Targets            |
  | `* Any` | `* Any`     | `* Any` | `Uncategorized`          | `Drop` | `Log` `Accounting` | `* Policy Targets` |

  **Important** - In such case, the Security Gateway / Cluster drops all TLS 1.3 traffic.

  See the [Security Management Administration Guide](https://support.checkpoint.com/product/184) for your version.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
