> Source: [sk182679](https://support.checkpoint.com/results/sk/sk182679)

# sk182679 - HTTPS Inspection Learning Mode recommendation

| Property | Value |
|----------|-------|
| Solution ID | sk182679 |
| Date Created | 2024-09-12 |
| Last Modified | 2026-02-26 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82 |
| OS | Gaia |

## Solution

**Table of Contents:**

* Overview
* Learning Mode Recommendation
* High CPU Utilization on the Security Gateway
* Low Success Rate of TLS connections through the Security Gateway
* Limitations

### Overview {#TOC01}

When the Learning Mode is enabled, it inspects a small percentage of the TLS traffic:

* To identify HTTPS connectivity issues.

* To estimate the expected CPU utilization on the Security Gateway based on the configured HTTPS Inspection policy.

The HTTPS Inspection percentage is automatically modified several times throughout a learning period of two weeks.

During this period, the Security Gateway collects as much information as possible about the CPU utilization and the connection success rate.

Later, the Security Gateway uses this information to predict both CPU usage and connection success rate when you enable full HTTPS Inspection.

### Learning Mode Recommendation {#TOC02}

1. In SmartConsole, from the left navigation panel, click the **Security Policies** view.

2. In the top left panel, click the **HTTPS Inspection** section.

3. In the bottom left panel **HTTPS Inspection** , click **Deployment**.

4. If the **Analysis and Recommendation** column shows this message:

   `Before enabling full inspection, see sk182679`

   Then click the ![](https://sc1.checkpoint.com/sc/images/sk_images/Important_Note.png) icon to see the CPU utilization and connection success rate statistics.

   Follow the applicable steps below based on the problematic metric.

### High CPU Utilization on the Security Gateway {#TOC03}

By design, inspecting TLS connections increases the CPU load, as many security features begin operating on the connection.

If the CPU utilization is too high, you must consult the Check Point sizing data to select the required appliance that can handle the traffic load. See the [Quantum Network Products](https://www.checkpoint.com/products/) and the [Appliance Sizing Tool](https://usercenter.checkpoint.com/ucapps/appliance-sizing-tool).

If you decided to continue using the same appliance and inspect TLS traffic, we recommend enabling full HTTPS Inspection **gradually**:

1. Configure the HTTPS Inspection policy to inspect the TLS traffic from specific clients or networks.
2. Keep monitoring the CPU utilization on the Security Gateway.
3. Gradually add more HTTPS Inspection rules until the Security Gateway reaches the maximum acceptable CPU utilization.

### Low Success Rate of TLS connections through the Security Gateway {#TOC04}

If the TLS connection success rate is lower than expected, consider these steps:

* Enable the bypass features:

  1. Enable the Client-Side Fail-Open feature.

  2. In the HTTPS Inspection policy, configure the Action "Bypass" for certificate pinned applications.

* Install the Check Point "Outbound CA" certificate as a Trusted Root CA on all corporate-managed assets.

  TLS clients that do not trust the Check Point HTTPS Inspection "Outbound CA" certificate cannot connect to servers over TLS.
* Update the "Trusted CAs Package" on the Security Gateway.

  Follow the steps in [sk64521](https://support.checkpoint.com/results/sk/sk64521).
* Make sure the TLS clients on your network support the latest TLS versions.

<br />

To monitor the flow of TLS connections through the Security Gateway, use any of these methods:

|---------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Monitoring Method                                                         | Instructions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Use the **HTTPS Inspection Statistics** view in SmartConsole or SmartView | Follow [sk182172](https://support.checkpoint.com/results/sk/sk182172). To see the log details: 1. In this **HTTPS Inspection Statistics** view, double-click the applicable chart or graph to see all the related session logs. 2. Double-click the applicable session log to see all the related connection logs (appear in the bottom panel). 3. Double-click the applicable connection log to see the complete log details.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Review the HTTPS Inspection logs in SmartConsole                          | 1. In SmartConsole, from the left navigation panel, click the **Logs \& Events** view. 2. In the left corner, click **Queries** \> expand the **Predefined** section \> click **HTTPS Inspection**. Alternatively, in the top **Filter** field, enter: `blade:"HTTPS Inspection"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Review the HTTPS Inspection logs in SmartView                             | 1. In a web browser, connect to SmartView: `https://<IP Address of Management Server>/smartview/` 2. At the top, click **\[+\]** to open a new tab. 3. In the left panel, click the **Logs** page. 4. Click the **Logs** widget. 5. In the top **Filter** field, enter: `blade:"HTTPS Inspection"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Use the **CPView** tool                                                   | 1. Connect to the command line on the Security Gateway. 2. Run: `cpview` See [sk101878](https://support.checkpoint.com/results/sk/sk101878). 3. At the top, click `Software-blades` \> `SSL-Inspection`. 4. At the top, click the `Overview` tab, scroll down, and refer to these sections: `Connection Bypass Reason:` `Errors:` Example output (truncated for brevity): Show / Hide this section ``` |---------------------------------------------------------- | CPVIEW.Software-blades.SSL-Inspection.Overview ... |---------------------------------------------------------- | Overview SysInfo Network CPU I/O Software-blades ... |----------------------------------------------------------- | Overview VPN SSL-Inspection IDA DLP Threat-Prevention ... |----------------------------------------------------------- | Overview Handshake |- More info available by scrolling up --------------------- | ... ... ... | ---------------------------------------------------------- | Connection Bypass Reason: | | Rule match on 5-tuple                           0 | Rule match on server name                       0 | Well-known update service                       0 | Inspection not required                         0 | Fail-open matching 5-tuple                      0 | Fail-open matching server name                  0 | Fail-open client side                           0 | Learning Mode                                   0 | Under heavy load                                0 | Certificate-pinned application                  0 |----------------------------------------------------------- | Errors: | | Client Hello parsing error            0 | Categorization error                  0 | Malformed record error                0 | |----------------------------------------------------------- ``` 5. At the top, click the `Handshake` tab and refer to this section: `Handshake` Example output (truncated for brevity): Show / Hide this section ``` |---------------------------------------------------------- | CPVIEW.Software-blades.SSL-Inspection.Handshake ... |---------------------------------------------------------- | Overview SysInfo Network CPU I/O Software-blades ... |----------------------------------------------------------- | Overview VPN SSL-Inspection IDA DLP Threat-Prevention ... |----------------------------------------------------------- | Overview Handshake |----------------------------------------------------------- | Handshake: | | Successful client handshakes        N/A | All client handshakes               N/A | Successful server handshakes        N/A | All server handshakes               N/A | ---------------------------------------------------------- | ... ... ... ``` |

### Limitations {#TOC05}

* The Learning Mode analysis is **not** synchronized between Cluster Members.

  In the event of a cluster failover, the analysis will start or resume on the other cluster member.

  Upon fallback, the Learning Mode analysis will resume from where it left off.
* By default, the Learning Mode analysis is maintained persistently on the Security Gateway / Cluster Members.

  To restart the analysis from scratch, clear the Learning Mode history:

  **Important** - Schedule a full maintenance window. This procedure completely stops all traffic.
  1. Connect to the command line on the Security Gateway / each Cluster Member.

  2. Log in to the Expert mode.

  3. Stop all Check Point services:

     `cpstop`
  4. Remove the Learning Mode history files:

     `/bin/rm -f $FWDIR/log/tlsi_dep/history/*.json`
  5. Start all Check Point services:

     `cpstart`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
