An administrator notices that Threat Emulation is failing to inspect encrypted HTTPS traffic traversing the Check Point security gateway. HTTPS Inspection is enabled globally, but malicious payloads inside SSL streams are bypassing emulation. What is the most likely root cause?
Trap 1: Threat Emulation blades are disabled globally inside the Threat…
Threat Prevention profiles apply inspection globally to all traffic streams once the underlying firewall policy permits the blade. The blade itself does not have a separate toggle specifically for encrypted traffic unless the decryption layer drops the connection entirely.
Trap 2: Threat Emulation only operates on layer 3 cleartext protocols and…
Check Point Threat Emulation integrates natively with Content Awareness and HTTPS Inspection architectures. It routinely processes extracted payloads regardless of whether the initial transport layer utilized standard HTTP or secure TLS wrappers.
- A
Threat Emulation blades are disabled globally inside the Threat Prevention profile for HTTPS traffic.
Why it fails: Threat Prevention profiles apply inspection globally to all traffic streams once the underlying firewall policy permits the blade. The blade itself does not have a separate toggle specifically for encrypted traffic unless the decryption layer drops the connection entirely.
- B
HTTPS Inspection rule base is bypassing the traffic or the Gateway lacks the correct internal CA certificate installed to perform SSL interception.
Interception relies on trusted internal Certificate Authorities deployed to endpoints. Without valid trust or if the rule explicitly bypasses inspection, the gateway cannot decrypt payloads, leaving files invisible to the Threat Emulation engine.
- C
Threat Emulation only operates on layer 3 cleartext protocols and cannot process content extracted from proxy-based architectures.
Why it fails: Check Point Threat Emulation integrates natively with Content Awareness and HTTPS Inspection architectures. It routinely processes extracted payloads regardless of whether the initial transport layer utilized standard HTTP or secure TLS wrappers.
- D
The Threat Extraction blade must be activated concurrently for emulation engines to receive decrypted file streams.
Threat Extraction and Threat Emulation are separate functional blades under the Threat Prevention umbrella. Emulation does not depend on Extraction being active to receive decrypted streams from the HTTPS inspection handler.