Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gerard2012
Explorer
Jump to solution

HTTPS Inspection Rule Not Being Matched

Hello all

 

In tried search forum for answer to this but nothing I've seen seems to work for me.

I'm have been tasked to enabled URL filtering to restrict access to internally hosted web apps.

I have enabled HTTPS inspection and have successfully blocked access to external HTTPS sites as a test, but for some reason the URL for this internal app is not matched in the inspection rules.

 

In this instance the CP software is R80.10.

 

The URL in question is:

https://ukst-webapp-utils-dev009.ase-dev.ourdomain.com/clientapp

 

I've tried every iteration of this in the Custom Application object...

"ukst-webapp-utils-dev009.ase-dev.ourdomain.com/clientapp"

"ukst-webapp-utils-dev009.ase-dev.ourdomain.com"

"ase-dev.ourdomain.com"

As regex...

".*\.ase-dev\.ourdomain\.com\/clientapp"

 

It just will not hit the inspection rule.

 

The server presents a wildcard cert for "*.ase-dev.ourdomain.com", is that significant?

It only works when I set the rule site category to "any", and then traffic seems to be classified as "Business / Economy".

Any advise would be greatly appreciated.

 

Thanks.

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

In R80.10, we match only based on the DN of the certificate.
Later versions support SNI (possibly requiring a JHF).
In any case, R80.10 is nearly End of Support and recommend upgrading.

View solution in original post

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

In R80.10, we match only based on the DN of the certificate.
Later versions support SNI (possibly requiring a JHF).
In any case, R80.10 is nearly End of Support and recommend upgrading.

0 Kudos
Gerard2012
Explorer

Thanks for responding so quickly PhoneBoy.

Yes, noted this needs to be upgraded, but to clarify, is it at all possible to match an inspection rule for a wildcard cert? If the the Custom Application object were just ...

".*\.ase-dev\.ourdomain\.com\"

for example?

 

0 Kudos
Gerard2012
Explorer

Just answered my own question.

Changed the URL in the object to "ase-dev.ourdomain.com" (not regex) and inspection works.

But will need upgrade to meet the requirements....

Thanks PhoneBoy.

0 Kudos
the_rock
Legend
Legend

I was just about to reply and suggest what you put in there. I ALWAYS use that method for allowing./blocking...*domain* and works fine : )

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events