> Source: [sk182907](https://support.checkpoint.com/results/sk/sk182907)

# sk182907 - HTTPS inspection certificate is triggered when accessing Captive portal or UserCheck

| Property | Value |
|----------|-------|
| Solution ID | sk182907 |
| Date Created | 2024-12-09 |
| Last Modified | 2024-12-30 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- HTTPS inspection is triggered when accessing Captive Portal. The IP (for example, `192.168.X.X`) uses `cert_60`, which is the IP and certificate associated with the following portals:

* Secure-Platform (Gaia Portal/Platform Portal)
* UserCheck
* NAC (Captive Portal)
* nac_transparent_auth (Captive Portal)

## Cause

The problem stems from using the same Fully Qualified Domain Name (FQDN) for both internal portals and Zero Phishing. This causes the expected certificate for internal portals to be overridden.

The GUI adds the FQDN to a `dns_pattern_certificates` entry, which overrides the certificate presented in the Server Name Indication (SNI). Typically, the FQDN for Zero Phishing should differ from that used by internal portals like UserCheck, as the Zero Phishing FQDN resolves to a public IP address.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
