- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Azure AD application proxy and HTTPS Inspection
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Azure AD application proxy and HTTPS Inspection
R81.10 Take 45, 5000 series appliance, non-VSX.
The customer has been evaluating this service from Microsoft.
Remote access to on-premises apps - Azure AD Application Proxy | Microsoft Docs
Everything works fine until HTTPS Inspection is turned on. From that moment, the rendering of applications becomes inconsistent with screen freezes, lag and so on. Unchecking HTTPS Inspection clears this.
Nothing is actually inspected as HTTPS Inspection is also being evaluated so the only initial actions were first to activate the service with a single rule any/any/any bypass upon which rules would be built. In the logs, all HTTPS traffic is shown as bypassed and all other HTTPS applications continue working.
The certificate has been regenerated, CA list updated, SecureXL off/on, failover, reboot, tried Ongoing Take 55, same result.
wstlsd.elg and drops debugs on traffic don't show any issues.
I wonder if anyone would have any hint on what else to check.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey,
Based on this "From that moment, the rendering of applications becomes inconsistent with screen freezes, lag and so on. Unchecking HTTPS Inspection clears this." an not knowing exactly what model of appliance you have, I could say you are seeing/hitting an appliance limitation.
Could it also be that the application you try to access through the Azure APP Proxy, requires some extra accesses/resources that are not allowed ?!?!?! Try with an simple app and see what you get .
The application freeze is when you try to reach from outside an internal application through Azure App Proxy?
How about the performance for browsing from inside to outside - that passes also through the same GW so you could clearly see and pinpoint the GW .
Thank you,
