Hi,
I have an issue with R80.10 Jumbo 275 on a Security Gateway.
I need that a server has only access to a specific URL (let's say https://www.perdu.com) without SSL inspection.
I've created an APP CTRL Rule allowing only the server to this specific site and a rule to bypass SSL inspection.
Below rule 4, the rule 5 is denying anything else.
data:image/s3,"s3://crabby-images/ac6fa/ac6fa73f23bf46a241a02c0d75ab5d34b0addb8a" alt="Image 004.jpg Image 004.jpg"
data:image/s3,"s3://crabby-images/cc5be/cc5bec1aeb46db236133fe7bbaea2c2f623e3023" alt="Image 005.jpg Image 005.jpg"
For some reason I can see that the SSL rule is matched (bypass) but the APP CTRL rule is not matched correctly and the request is Droped when I use SSL. With HTTP it is working fine.
data:image/s3,"s3://crabby-images/844e8/844e8b6ff2610cdf093f5efe331f182348164ff1" alt="Image 001.jpg Image 001.jpg"
data:image/s3,"s3://crabby-images/6f6ab/6f6ab3509be9d07d8e0c873ff42f064aa3bc49ef" alt="Image 002.jpg Image 002.jpg"
data:image/s3,"s3://crabby-images/2ed58/2ed58912b5714bdb9606c955f7121eb34d2f9f77" alt="Image 003.jpg Image 003.jpg"
The Probe Bypass is conifugred that way [Expert@firewall:0]# fw ctl get int enhanced_ssl_inspection
enhanced_ssl_inspection = 1
[Expert@firewall:0]# fw ctl get int bypass_on_enhanced_ssl_inspection
bypass_on_enhanced_ssl_inspection = 0
[Expert@firewall:0]#
I think it has something to do with the fact that I am not doing SSL insepction, and that the gateway can't find the server name.
Any ideas how I can deal witht his config. Of couse I don't want to add the IP addess of the web server as it may change over time
Thank you