# HTTPS Inspection: one site still warns

Source: https://ai.techclick.in/blog_checkpoint_https_inspection_one_site_warns
Markdown: https://ai.techclick.in/blog_checkpoint_https_inspection_one_site_warns.md
Publisher: Techclick Infosec Pvt Ltd

HTTPS Inspection decrypts TLS with your CA. One site still warns because of bypass miss, pinning, or the client missing the CA. Dummy hr.techclick-lab.in vs bank site.

## The ticket

 Most of the LAN is fine. One SaaS URL warns NET::ERR_CERT_AUTHORITY_INVALID — or only the vendor thick client fails. Helpdesk wants Inspection off globally. You need the one-site reason.

  Quick interview answer

 HTTPS Inspection terminates TLS, inspects, and re-encrypts with a CA you created. Clients must trust that CA. Sites that pin certificates, use mutual TLS, or sit in a bypass category must be excluded. A warning on one site is usually: client lacks CA, site should be bypassed, or SNI/category missed the bypass rule.

   Hero · one warning

   One red triangle is a bypass or CA problem, not a reason to kill Inspection for the company.

  Lab data · dummy only
 SMS  sms-lab   10.10.10.5  · cluster VIP  10.10.10.1  ( cp-gw-01   10.10.10.2  /  cp-gw-02   10.10.10.3 ) · external  203.0.113.25  · internal LAN  10.20.30.0/24  · HR PC  10.20.30.80   TECHCLICK\priya.hr  · HR app  10.20.30.41   hr.techclick-lab.in . Not a live customer.

## What Inspection is

 Without Inspection the gateway sees SNI/IP and a TLS tunnel. With Inspection it presents a forged cert signed by  your outbound CA . Threat Prevention and App Control then see HTTP inside.

 The client validates that cert. If the CA is not in the trust store, the browser warns. If the app pins a public CA leaf, it will break even when the browser is happy.

## Inspect vs bypass

   Decision  When  Proof

  Inspect  General web, where you need URL/TP inside TLS  Log: Inspected
  Bypass category / custom list  Banks, health, pinned SaaS, client-cert apps  Log: Bypass
  Do not inspect inbound to your own published site unless designed  Inbound TLS to Static NAT web  Separate inbound HTTPS Inspection policy if used

     smartconsole://sms-lab/policy/https

     Training mock · not live

       SmartConsole · lab

       Gateways &amp; Servers  Security Policies  Logs &amp; Monitor  Manage &amp; Settings

       Security Policies → Access Control → HTTPS Inspection

### HTTPS Inspection policy

        Source  net_lan

  Destination  Internet

  Action  Inspect

  Bypass  Financial / Health + custom grp_pinning

  CA  Lab_Outbound_CA

        Cancel  OK

   HTTPS Inspection Admin Guide — Inspect vs Bypass actions; deploy CA to clients. Training mock.

## How you configure it

- #### Side A — CA to clients Export the outbound CA. GPO / MDM into Trusted Root. Thick clients may need their own store.

- #### Side B — policy HTTPS Inspection blade on the gateway. Inspect LAN→Internet. Bypass pinned names and sensitive categories. Install Access Control (Inspection lives with it).

- #### Side C — one site Browser cert viewer: issued by Lab_Outbound_CA or by the real public CA? Log action Inspect vs Bypass. Then add a precise bypass or fix CA deployment.

  What to read · dummy  # Client: click the padlock
# Issued by: Lab_Outbound_CA     → Inspection happened
# Issued by: DigiCert / Amazon    → Bypass or not inspected

# SmartLog: HTTPS Inspection action
# Inspected + client warn = CA not trusted on THAT device
# Inspected + app fail + browser ok = pinning
# Bypass + you expected inspect = category/SNI miss

## Four Inspection failures

### 1 · One PC warns, others fine

 That PC missed GPO. Not a gateway bug.

### 2 · One site warns everywhere

 Bypass miss or the site sends a cert the gateway cannot validate (need bypass or different inspect setting).

### 3 · Pinning

 Browser OK (trusts your CA). Vendor EXE fails. Bypass that FQDN. Do not disable Inspection org-wide.

### 4 · Inspection + Identity captive portal

 Portal must be reachable without a warn loop. Exempt the portal object.

## How to prove it

  Close the ticket only when

 1) You know Inspect vs Bypass for that FQDN. 2) Cert chain on a working PC shows Lab CA when inspected. 3) The one broken site is either bypassed or the one PC got the CA. 4) Inspection still on for the rest of the LAN.

## Traps

   Symptom  Story  First proof  Wrong fix

  One PC warns all sites  CA missing  certmgr / GPO  Disable blade
  One FQDN, all PCs  Bypass / validate fail  Log action  Any-Any bypass
  App fail, browser ok  Pinning  Issued-by Lab CA  Reimage gateway

## Knowledge check

   Judgment items. One best answer. Reasons send you back to the matching section.

       Q1
       Clients must trust what for outbound HTTPS Inspection?

           The gateway’s outbound CA
           SIC activation key
           Cluster VIP only
           Hide NAT IP

       Correct:  a . Concept.

       Q2
       Browser OK, vendor EXE fails on the same URL. Likely?

           Certificate pinning
           SIC down
           No default route
           Cleanup missing

       Correct:  a . Failure 3.

       Q3
       One PC warns on every HTTPS site. First check?

           That PC’s trusted-root CA
           Reinstall SMS
           cphaprob
           fwaccel off

       Correct:  a . Failure 1.

       Q4
       Correct one-site fix for a pinned bank app?

           Bypass that FQDN/category
           Turn off Inspection for the company
           Delete Access Roles
           Static NAT the bank

       Correct:  a . Choose table.

       Q5
       Log says Bypass but you expected Inspect. Meaning?

           A bypass rule/category hit first
           Gaia DNS is down
           Hide NAT failed
           Implied accept

       Correct:  a . Proof block.

       Q6
       Issued by Lab_Outbound_CA on a warning PC means?

           Inspection happened; the PC does not trust the CA
           Inspection is off
           Static NAT broke
           Cluster is down

       Correct:  a . Runbook Side C.

       Check answers
       Reset

  Check Point class series:   Architecture  ·  Gaia first day  ·  SIC reset  ·  Objects + first match  ·  Policy layers  ·  Hide vs Static NAT  ·  Identity Awareness  ·  HTTPS Inspection  ·  Threat Prevention  ·  Find the drop  ·  fw monitor  ·  SecureXL  ·  ClusterXL  ·  VPN Community  ·  Policy install lock  ·  vs PA vs Forti  ·  CCSA / CCSE interview

## Sources

- Check Point HTTPS Inspection Administration Guide (R81 / R81.20) — Inspect/Bypass, outbound CA, inbound vs outbound.
- Current SK for HTTPS Inspection troubleshooting (certificate errors, bypass).

 Related:  Check Point evidence desk  ·  session factory  · next lesson in the series above.

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
