Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Markus_Marquard
Contributor

Best practice to exempt sites from HTTPS inspection

Hi,

what is best practice to exclude sites - identified by hostname - from https inspection?

We cannot use host objects as the ip addresses behind the FQDNs can change without notice.

We would like to use FQDN (R80.10) objects, but unfortunately it seems they are NOT supported in HTTPS inspection policy. Is there a plan to implement this?

So we are ending up with creating custom URLs? But this will still have some impact on the (at least 1st) HTTPS connection to this destination as the firewall has to check the first packet for URL.

Any thoughts?

3 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events