Monitoring HTTPS Inspection When Security Gateway Works with HSM
When HTTPS Inspection Feature on a Security Gateway that inspects traffic encrypted by the Secure Sockets Layer (SSL) protocol for malware or suspicious patterns. Synonym: SSL Inspection. Acronyms: HTTPSI, HTTPSi. daemon wstlsd initializes on a Check Point Security Gateway
Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. / Cluster Member
Security Gateway that is part of a cluster. / Scalable Platform Security Group
A logical group of Security Appliances (in Maestro) / Security Gateway Modules (on Scalable Chassis) that provides Active/Active cluster functionality. A Security Group can contain one or more Security Appliances / Security Gateway Modules. Security Groups work separately and independently from each other. To the production networks, a Security Group appears a single Security Gateway. In Maestro, each Security Group contains: (A) Applicable Uplink ports, to which your production networks are connected; (B) Security Appliances (the Quantum Maestro Orchestrator determines the applicable Downlink ports automatically); (C) Applicable management port, to which the Check Point Management Server is connected., it checks whether this Security Gateway / Cluster
Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. Member / Security Group is configured to work with an HSM Server.
-
You can see the applicable logs in SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. > Logs & Monitor > Logs tab.
See Monitoring HTTPS Inspection with HSM in SmartConsole Logs.
-
You can query the HTTPS Inspection on the Security Gateway / Cluster Members / Security Group over SNMP.
-
You can run the "
cpstat https_inspection
" command on the Security Gateway / Cluster Members / Security Group.
|
Note - To see detailed information about wstlsd initialization, follow sk105559: How to debug WSTLSD daemon. |