Hi, we have the HTTP/S proxy set to transparent but we do not currently want HTTPS traffic checked. Is there a way to exclude HTTPS traffic so it can be viewed in a browser etc?
This thread was automatically locked due to age.
Chris,
In "Transparent" mode, HTTPS traffic is not handled by the proxy unless 'Scan HTTPS (SSL) Traffic' is checked on the 'Global' tab.
Usually, when people first install Astaro, they cause the setup wizard to create a packet filter rule like 'Internal (Network) -> Web Surfing -> Any : Allow', and that includes HTTPS traffic. If that rule isn't active, then you at least would need a packet filter rule like 'Internal (Network) -> HTTPS -> Internet : Allow'.
Cheers - Bob
Chris, what do you see in the Packet Filter log? If there's no hint there, check the Intrusion Prevention log.
Cheers - Bob
Forgot to mention. I say try internal network or even 'any' since I'm not sure if 'All' which you referenced is your own creation or you meant our ANY
Do I have to mention, that ANY - ANY - ANY is bad, if a Internet connection is connected ? [:D]
However, usual failure if packetfilterrule to Internet does not work is, that you have forgot to create a masquerading rule under Network Security / NAT