Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Zolo
Collaborator
Collaborator

R81.20 Inbound SSL inspection - custom applications are not working

Hello,

Is it poosible to filter SNI sites with custom application?

Source: Any(Internet clients)
Destination: SNI host Public IP
Service: HTTPS
Custom Application: mydomain.com object (Contain: mydomain.com, No Regex)
Action: Inspect
Certificate: mydomain.com cert (Contain: CN=example.com, SAN DNS: mydomain.com)

I tried with regex as well, with no luck.

Br,
Zolo

 

 

 

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

What version/JHF are you on?

As far as I know, this should work.
When you say "no luck" what is the exact behavior?
Please show screenshots of any log entries, behavior, etc (redact sensitive details). 

0 Kudos
Zolo
Collaborator
Collaborator

In the customer's environment the version is R81.20 JHF T99

But I tried in CP Demo Point (where I also upgraded to the latest version both the management and the gateway) with the same result.
"no luck" I ment that the result was the same, not worked.

I try to fnd some time to reproduce and I will post logs and screenshots.

0 Kudos
the_rock
Legend
Legend

100% it does work. I dont have access to my lab to test it for couple weeks, but if you can send error or some sort of log, would help.

Andy

0 Kudos
Zolo
Collaborator
Collaborator

There is no error, simply do not match to that rule.
If I define an another rule with connection Bypass that rule matches.

I try to fnd some time to reproduce and I will post logs and screenshots.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events