we have a strange behaviour with ssl protocol and application control.
customer notify us that some sites that should be blocked by the application control were accessible (like facebook)
rules are configured in whitelist mode (allowing specific categories and applications and a block all rule a the bottom)
after investigating we notice that there was an application control rule that enabled https to internet that allow facebook and many other sites, once disabled that rule all these sites were correctly blocked by the application control rules but we got also lot's of traffic blocked as "SSL protocol" and we needed to recover the rule.
how can we enable ssl protocol and block these sites at the same time?
one solution would be to change the policies to a blacklist mode but the customer want to keep the rules in whitelist mode.