Hi there,
I've seen that HTTPS traffic is now handled by the proxy in transparent mode also if I don't scan https traffic. I no more need an extra firewall rule for https traffic.
Just rebuilt on 9.195. Global filtering "Transparent Mode" "URL filtering only". New profile for 1 IP "Transparent Mode" "Do not scan" with a copy of the base filter action. No firewall rule to allow HTTPS and the client in question is blocked. Add a rule to allow HTTPS and the client can go HTTPS with no web filter log entries.
I added Google to the filter action for that profile and found that it was blocked via HTTP successfully but only blocked by the firewall over HTTPS.
Just rebuilt on 9.195. Global filtering "Transparent Mode" "URL filtering only". New profile for 1 IP "Transparent Mode" "Do not scan" with a copy of the base filter action. No firewall rule to allow HTTPS and the client in question is blocked. Add a rule to allow HTTPS and the client can go HTTPS with no web filter log entries.
I added Google to the filter action for that profile and found that it was blocked via HTTP successfully but only blocked by the firewall over HTTPS.