This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cisco Webex and Decrypt & scan HTTPS issue

Hi

 

I am trying to get audio to connect within a Cisco webex meeting.

 

If i disabled Decrypt & scan HTTPS or add my IP to exceptions the audio connects fine.

I have exceptions for each domain listed on https://help.webex.com/en-us/WBX264/Network-Requirements

They are all added in the following format

Looking through the web filter logs I do not see any other domains while trying to connect to the audio. So it appears they are all covered.

 

Is there any other reason the XG keeps putting itself between the PC and Cisco when doing the audio connections? Not sure were else to look on the XG for what is triggering this.



This thread was automatically locked due to age.
Parents
  • I suspect you will need to add an application policy to your firewall rule to allow the webex application to work.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • I have tried with none and the default "Block high risk" application options in the firewall rule.

    It made no difference. I also see no blocked logs in the application logs while connecting to a webex.

     

  • Hi,

    what rule does the log viewer show as the PC tries to connect. Ad a filter to your logviewer of the IP address of your PC.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Not too sure what you mean.

     

    I have a firewall rule with an ID of 5. In the logs it either says firewall rule 5 or 0.

     

    The ones matching rule 0 normally say 

    Could not associate packet to any connection.
     

     

     

    However I only see green when i am connecting the audio.

  • Firewall rule 0 is the default firewall block/drop all. Basically it means your firewall rule has some filtering that the software doesn't like or does not match.

    Please post a expanded copy of your firewall rule.

     

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • I have another rule that I did some testing with that just allowed any service to the WAN. Did not make any difference.

    This is rule 5 - If i turn off the decrypt and scan https it all works fine.

     

  • I should mention right below this I have the following rule. So anything rejected should show up as a match to rule #12

     

  • Hi,

    you don't need this rule, the firewall already has one.

    For testing setup a rule at the top of your list.

    Source LAN ,your PC IP address, destination WAN, any

    MASQ.

    Log traffic

    Setup logviewer to display this rule using a filter.

    Setup a call and see what traffic is passed, then display the results here.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hi,

    you don't need this rule, the firewall already has one.

    For testing setup a rule at the top of your list.

    Source LAN ,your PC IP address, destination WAN, any

    MASQ.

    Log traffic

    Setup logviewer to display this rule using a filter.

    Setup a call and see what traffic is passed, then display the results here.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Children