We'd love to hear about it! Click here to go to the product suggestion community
I need to be able to exclude Splashtop and logmein from SSL Inspection for them to work. I tried ^[A-Za-z0-9.-]*\.splashtop\.com/ which lets me connect through the client, but I am not able to remote into any machines. I am assuming that is because the remote aspect must be using another URL that is not covered under this expression. Anyone have experience with this one?
UPDATE: I found these on splashtop site
This is what I added into the Sophos exclusion list I have created and still does not work
I am struggling with this EXACT problem!! were you able to find a solution??
In reply to Justin Rutledge:
So far no. I am still doing testing trying to come up with something. I have a Sophos Engineer looking into this on Wednesday with me. I will update this post once we figure it out.
In reply to Chris Wright:
Any insight at all today on this Chris? I am digging myself trying to find something, and it is getting quite frustrating to be honest.
Justin, so I reached out to splashtop and Sophos on this issue. The problem is Splashtop is using Amazon AWS for their remote connections and every connection is a different ip address. They are not using DNS so there is no way to allow splashtop in that that method. They recommended me to allow all of AWS Ip's.. Thats nuts. The best Sophos could do for me is we added the web category IPAddress which means that anything that is not resolving DNS and is just an IP address does not get filtered. This is the same issue with logmein the connection will not work unless I allow IPAddress in web categories. This is an issue with the way they handle their connections. If we could get an actual DNS name to these connections we could allow at the domain level.
Thank you very much for getting back to me! That all makes sense, but man what a pain. At first glance that seems like a bit of an unsafe hole to punch in the firewall, but I'll have to think about it some more. What a crazy thing that someone would not be using dns...
Could you expound on what settings you put in the web category to get splashtop through? Running into the same problem. Thank you.
Besides the 2 sets of DNS servers needed for Splashtop (*.api.splashtop.com and *.relay.splashtop.com), Splashtop sets up end to end encryption. Therefore, there will be "non-ssl" packets through port 443. Please see this article for complete information:
If the check tool - www.splashtop.com/check - passes, then it is likely the non-ssl packets on port 443 are being blocked by inspection.