Enable Mutual TLS (mTLS) Authentication | Check Point WAF

Overview

Mutual TLS (mTLS) enhances security by requiring both the server and the client to authenticate each other using digital certificates. When mTLS is enabled, only clients presenting valid certificates signed by a trusted Certificate Authority (CA) can successfully establish a connection.

This guide explains how to upload a trusted CA list, apply the configuration, and enforce the mTLS policy through the asset’s Advanced Settings interface, in in Gateway / Virtual Machine and Single Docker.

Prerequisite

Instructions to Configure mTLS on

  1. Navigate to the asset you wish to protect.

  2. Open the Advanced Settings section.

  3. Locate the Client SSL Verification configuration option.

  4. Select the checkbox labeled Trusted CA list for client SSL verification.

  5. Click Upload, then select and upload your CA certificate ( .pem) file.

  6. The uploaded CA list defines which client certificates are trusted for authentication.

  7. Verify that the file name appears in the upload field once the upload completes.

  8. Save and Apply Configuration.

  9. Click OK to save your changes.

  10. Click Enforce to synchronize the updated configuration to your agents.

  11. Once enforced, clients will be required to present valid certificates during connection attempts.

Configuring Multiple CA Certificates

If you need to trust more than one Certificate Authority, you can combine multiple CA certificates into a single .pem file.

To do this:

-----BEGIN CERTIFICATE----- (CA Certificate #1 contents) -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- (CA Certificate #2 contents) -----END CERTIFICATE-----

WAF SaaS CA Certificate Requirements

Each certificate in the uploaded CA list must meet the following requirements:

mTLS is not supported in WAF SaaS profile for the following special configurations: