Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Contributor

Does SSL Inspection Affect Azure Integration?

Hi forum,

My azure integreation failed recently and I think it relates to the Managment Servers Azure HTTP calls being routed through the firewall that's doing the SSL inspection.  So I am expecting the SSL validation to fail as the Management server lacks the root certificate in it's trust store to verify the firewall masquerading as microsoft to be geniune.

Anyone had this?  I will start digging deeper but I just wanted to run it past you guys - thanks!

Nik

5 Replies
Admin
Admin

My first guess would be that you need to exclude the management from HTTPS Inspection.

There may be another way to achieve this (for example add the CA key to the root store used by the CloudGuard Controller).

Will check.

0 Kudos
Reply
Contributor

Hi dameon,

yeah i wasn’t sure if I could treat Gaia like any other Linux box and update the cert store then find out TAC won’t support me anymore  

got to say... arrgghh... I didn’t realise you could exclude ssl inspection so I’ll google that but I’m not too sure what the targets are for the azure API 

really appreciate the help - I’ll post up any solution I find that works for me too!!!  

Hi Nicholas,

I am not 100% sure, but could you check if the Mng Server is conneting to management.azure.com  for the Azure Integration ? May be login.windows.net is also used

Best Regards

Matthias

Admin
Admin

Just to come back to this thread, you should be able to add the relevant HTTPS Inspection certificate to $CPDIR/conf/ca-bundle-public-cloud.crt on the gateway.

Then execute vsec stop; vsec start to activate it.

0 Kudos
Reply
Contributor

Dameon Welch-Abernathy‌ thanks - I'll give that a shot and advise! Smiley Happy

0 Kudos
Reply