This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL inspection migrate from Fortinet to Sophos XG

Hi there,

As i'm on an BYOD environment i want to only enable SSL inspection like Fortigate does by checking SNI requests (without installing certificate on each device).

I know it is less precise especially for cloud apps but it will deserve what we want.

How could it be done on MR4 ? Thanks.

Anaël ROLAND



This thread was automatically locked due to age.
Parents
  • Hello,

    On Sopohs XG It works in the same way, you can choose between decrypting the entire connection or just analyzing the Certificate.

    By default on v18 the DPI Engine is always checking all TLS connection and It's certificates, if you create a Web Policy for your users, It will automatically enforce It on both HTTP & TLS Connections, over all ports & applications. *Depends on how you configure the Firewall Rule.

    Another thing, you can enforce anything you want on the TLS Session (By creating Don't Decrypt Rules), such as blocking TLS 1.0 or TLS 1.1, or even blocking insecure ciphers without having to decrypt the connection (Import a certificate)

    You can check more information about this, at the Docs.

    Thanks!

Reply
  • Hello,

    On Sopohs XG It works in the same way, you can choose between decrypting the entire connection or just analyzing the Certificate.

    By default on v18 the DPI Engine is always checking all TLS connection and It's certificates, if you create a Web Policy for your users, It will automatically enforce It on both HTTP & TLS Connections, over all ports & applications. *Depends on how you configure the Firewall Rule.

    Another thing, you can enforce anything you want on the TLS Session (By creating Don't Decrypt Rules), such as blocking TLS 1.0 or TLS 1.1, or even blocking insecure ciphers without having to decrypt the connection (Import a certificate)

    You can check more information about this, at the Docs.

    Thanks!

Children