Who rated this post

cancel
Showing results for 
Search instead for 
Did you mean: 
PhoneBoy
Admin
Admin

Part of performing HTTPS Inspection requires the gateway to reach out to the destination server to verify SNI.
If the gateway can't do this, you'll get this error.

If the gateway is attempting to reach out to the server without going through the VPN, you should clearly see this in a tcpdump on the external interface.
If the destination is in the encryption domain, it should go over the VPN.
If it isn't it might be a bug and TAC should be engaged.

View solution in original post

0 Kudos
(1)
Who rated this post