This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Firewall HTTPS Scanning outside the broswer

I have installed the HTTPS Scanning certificate as per the knowledge base on the computers in our office.

i have installed the certificate in the trusted root of the local machine and ensured the browsers are configured correctly as well.

i have no/minor issues using the https scanning when viewing webpages.

however i am running into an issue with certain apps.

for example, one user uses roboform and is unable to sync their account when https scanning is enabled for their workstation, the same goes for another user that is using teamspeak, their account will not sync.

from what i can see there is an certificate error being thrown in both apps but i cannot find out why exactly.

 

adding addresses to the exceptions list in the device does not seem to work.



This thread was automatically locked due to age.
Parents
  • Hey  

    Unfortunately this is the case with certain applications, as they have their certificates built in or other factors.

    Are you able to contact the application vendor for a list of destination addresses to assist with your exception list? Note that this may be difficult to administrate depending on the application, as you may have to continue maintaining this list if the addresses are continually changing.

    Your other options include bypassing HTTPS scanning per Web Category or per source IP (though this bypasses the entire computer).

    For reference, see this community thread.

    Regards,

Reply
  • Hey  

    Unfortunately this is the case with certain applications, as they have their certificates built in or other factors.

    Are you able to contact the application vendor for a list of destination addresses to assist with your exception list? Note that this may be difficult to administrate depending on the application, as you may have to continue maintaining this list if the addresses are continually changing.

    Your other options include bypassing HTTPS scanning per Web Category or per source IP (though this bypasses the entire computer).

    For reference, see this community thread.

    Regards,

Children
No Data