Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Alex-
Advisor

Azure AD application proxy and HTTPS Inspection

R81.10 Take 45, 5000 series appliance, non-VSX.

 

The customer has been evaluating this service from Microsoft.

 

Remote access to on-premises apps - Azure AD Application Proxy | Microsoft Docs

Everything works fine until HTTPS Inspection is turned on. From that moment, the rendering of applications becomes inconsistent with screen freezes, lag and so on. Unchecking HTTPS Inspection clears this.

Nothing is actually inspected as HTTPS Inspection is also being evaluated so the only initial actions were first to activate the service with a single rule any/any/any bypass upon which rules would be built. In the logs, all HTTPS traffic is shown as bypassed and all other HTTPS applications continue working.

The certificate has been regenerated, CA list updated, SecureXL off/on, failover, reboot, tried Ongoing Take 55, same result.

wstlsd.elg and drops debugs on traffic don't show any issues.

I wonder if anyone would have any hint on what else to check.

0 Kudos
1 Reply
Sorin_Gogean
Advisor

Hey,

 

Based on this "From that moment, the rendering of applications becomes inconsistent with screen freezes, lag and so on. Unchecking HTTPS Inspection clears this." an not knowing exactly what model of appliance you have, I could say you are seeing/hitting an appliance limitation. 

Could it also be that the application you try to access through the Azure APP Proxy, requires some extra accesses/resources that are not allowed ?!?!?! Try with an simple app and see what you get .

 

The application freeze is when you try to reach from outside an internal application through Azure App Proxy?

How about the performance for browsing from inside to outside - that passes also through the same GW so you could clearly see and pinpoint the GW .

 

Thank you,

 

0 Kudos