Firewall-1

[FW-1] Bypassing "CONNECT command found in HTTP request"

Subject: [FW-1] Bypassing "CONNECT command found in HTTP request"
From: David Landgren <david AT LANDGREN DOT NET>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Mon, 31 Jan 2005 16:59:21 +0100
Hello List,

I recently upgraded my firewall. It says here:

This is Check Point VPN-1(TM) & FireWall-1(R) NG with Application
Intelligence (R55) HFA_12, Hotfix 309 - Build 007

I am experiencing a rather annoying problem with https traffic. People
on the same segment as our web proxy have no problem, since they hit it
directly. The rest of the users come in through the VPN, and hence are
routed across the firewall. All their https traffic is being dropped by
the firewall because it sees a "CONNECT command found in HTTP request".

I have looked at the knowledge base and there appear to be a couple of
recipes that deal with this problem, however, I am loathe to try one out
at random. Has anyone experienced this problem beforehand and resolved
it successfully?

thanks,
David Landgren

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>