Solved: Inbound HTTPS Inspection - Custom client certifica... - Check Point CheckMates
Inbound HTTPS Inspection - Custom client certificate required
Hi Everyone!
We have a use case where we need to deploy inbound HTTPS Inspection to a specific web service that uses a non standard port.
Gateways and management are both running R80.40.
Initially we are seeing a Bypass with the following error "Internal system error in HTTPS Inspection (Error Code: 2)"
One of the possible causes is that the root certificate is not trusted, however the customer is using the same cert in other inbound inspection rules without issues.
While troubleshooting we found that the backend application requires the client to send a specific certificate.
Since we are doing a Man-in-the-middle (MITM) for inspection it's obvious that the connection between the Gateway and the server will have the Check Point self signed certificate, not the one required by the application.
I know that this use case can be solved with an ADC such as F5, Netscaler, A10.
Questions:
- Can we do it with Check Point? I didn't find a proper way of using specific client certificates (Not server certs) for specific connections within the admin guides or SKs.
- Can "Internal system error in HTTPS Inspection (Error Code: 2)" be related to this issue? An HTTPS debug is not possible for the moment due to maintenance window requirements.
Thanks!
____________
https://www.linkedin.com/in/federicomeiners/
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
1 Solution
Accepted Solutions
Admin
2020-10-2107:06 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
AFAIK, we do not have such functionality available. Try raising and RFE with your local Check Point team. Meanwhile, you will have to create a bypass rule for this application to work
View solution in original post
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
4 Replies
Admin
2020-10-2107:06 AM
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Advisor
2020-10-2109:25 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Valeri,
Thanks for the quick response! Just wanted to be sure of my assumptions.
It would be nice feature however it's not the job of a NGFW 🙂
Will work on the RFE with my local SE.
Thanks!
Federico
____________
https://www.linkedin.com/in/federicomeiners/
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Participant
2021-10-0603:30 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In response to FedericoMeiners
I know this thread is maybe already outdated,
but i'm very interested in case there was a response to the RFE.
I do have a similar requirement.
\* HTTPS inbound inspection should be used to inspect traffic.
\* Server requires certificate based client authentication
My quick check:
Server tcpdump:
- Server Hello, Certificate, Certificate Request, Server Hello Done
Server Application Log:
- HTTPS client connection from host {FW-IP} failed due to the SSL error:
(sec.core-114) SSL connection error (peer did not return a certificate).
The behavior is, that this connection will time out.
Firewall log doesn't show Error Code-2
(what is in my experience mostly missing CA cert in list of Trusted CA or failed OCSP/CRL check)
Our competitor PA offers for such cases an interesting " nonProxy / forwarding mode".
As they have the private key and key exchange is RSA (not PFS),
then the firewall can simply copy and decrypt the https traffic for inspection. (PA is not MITM)
SSL Inbound Inspection (paloaltonetworks.com)
Does Check Point support such a mode?
@FedericoMeiners: Did you raised an RFE?
Thanks,
Ciao Martin
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Admin
2021-10-0603:55 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe as part of our NDR offering we have something that can do this.
The feature is called Cooperative Inspection.
Note that NDR sensors run a different image and are managed differently from regular Check Point gateways.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Post Reply
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
israelfds95 |
13 |
HeikoAnkenbrand |
7 |
simonemantovani |
5 |
emmap |
3 |
Steffen_Appel |
2 |
Kaspars_Zibarts |
1 |
Alex- |
1 |
Danny |
1 |
Bob_Zimmerman |
1 |
DH |
1 |
Trending Discussions
Five Habits That Improved My Check Point Deployments
Automatically Renew VPN Certificates
Snapshot and /boot disk space full
Upcoming Events
Sort by:
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats
Wed 29 Jul 2026 @ 12:00 PM (SGT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT
Wed 29 Jul 2026 @ 02:00 PM (IDT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER
Wed 29 Jul 2026 @ 03:00 PM (CEST)
The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA
Wed 29 Jul 2026 @ 11:00 AM (EDT)
TechTalk: On-Premise SD-WAN Management
Thu 30 Jul 2026 @ 11:30 AM (CDT)
CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Wed 29 Jul 2026 @ 12:00 PM (SGT)
Wed 29 Jul 2026 @ 02:00 PM (IDT)
Wed 29 Jul 2026 @ 03:00 PM (CEST)
Wed 29 Jul 2026 @ 11:00 AM (EDT)
TechTalk: On-Premise SD-WAN Management
Thu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway
Tue 11 Aug 2026 @ 11:30 AM (EDT)
New York City: Agentic AI Security Deep Dive & Hands-On
Thu 13 Aug 2026 @ 11:30 AM (EDT)
Waltham, MA: Agentic AI Security Deep Dive & Hands-On
Thu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA
Thu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad
Thu 27 Aug 2026 @ 09:00 AM (CEST)
Check Point Hands-On SASE and Cloud Workshop - Zurich
Wed 21 Oct 2026 @ 09:00 AM (BST)
AI Security Workshop - Glasgow
About CheckMates
Learn Check Point
Advanced Learning
Resources
Non-English Discussions
YOU DESERVE THE BEST SECURITY
We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram
©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.