Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

TLS Exclusion list Do not decrypt but Logmein show certificate from Sophos XGS firewall

Hello,

we have XGS 136 firewall with enabled SSL/TLS inspection
All workstations have Logmein installed.
Sophos Firewall Certificate is installed on workstation trusted certificate in local computer storeOn XFS firewall I have create Logmein Local TLS exclusion list for Logmein and also Web Exception (HTTPS decryption & HTTPS certificate validation)

When I disable SSL/TLS inspection I can connect to workstation with Logmein
When SSL/TLS inspection enabled I can NOT connect.


Local TLS exclusion list: logmein.com

URL pattern matches
^([A-Za-z0-9.-]*\.)?logmein\.com/
^[A-Za-z0-9.-]*\.[A-Za-z0-9.-]*\.logmein\.com/


screenshots:

No connection

LocalComputerCertificateTrusted

With disabled SSL/TLS inspection

How can I make correct exception for Logmein?

Example of Logmein connection URL
control.lmi-app20-05.logmein.com
control.lmi-app20-06.logmein.com
control.lmi-app20-07.logmein.com
control.lmi-app20-08.logmein.com
control.lmi-app03-10.logmein.com
control.lmi-app03-13.logmein.com
console-efuexvrqrs.lmi-app20-05.logmein.com
console-bybvznvduz.lmi-app20-07.logmein.com
console-agnyxrrvqk.lmi-app20-08.logmein.com

XGS LOG SSL-TLS-inspection-log



This thread was automatically locked due to age.
Parents Reply
  • yes, I know, the list of Logmein is almost Endless  ;)
    https://support.logmeininc.com/gotoassist-remote-support/help/whitelisting-and-firewall-configuration

    I have checked my Firewall Log SSL/TLS inspection and there are only the *.logmein.com Servernames

    My current list for Logmein Web protection exception

    URL pattern matches
    ^([A-Za-z0-9.-]*\.)?logmeinrescue-enterprise\.com/
    ^([A-Za-z0-9.-]*\.)?webservice\.logmein\.com/
    ^([A-Za-z0-9.-]*\.)?logmeinusercontent\.com/
    ^([A-Za-z0-9.-]*\.)?browse\.logmeinusercontent\.com/
    ^([A-Za-z0-9.-]*\.)?accounts\.logme\.in/
    ^([A-Za-z0-9.-]*\.)?logmeinrescue\.com/
    ^[A-Za-z0-9.-]*\.[A-Za-z0-9.-]*\.logmein\.com/
    ^([A-Za-z0-9.-]*\.)?logmeininc\.com/
    ^([A-Za-z0-9.-]*\.)?boldchat\.com/
    ^([A-Za-z0-9.-]*\.)?logmein\.com/
    ^([A-Za-z0-9.-]*\.)?internapcdn\.net/


    and my Logmein Exceptions IP
    64.74.0.0/19
    64.74.112.0/20
    64.95.128.0/21
    69.88.148.0/22
    95.172.68.0/22

Children