I followed the procedures here: https://community.sophos.com/kb/en-us/123048
However, I cannot reach any websites anymore, such as google, yahoo, etc, after I have checked the box to "decrypt and scan https" in my firewall rule. What am I doing wrong?
I have tried restarting the browser, rebooted the computer, removing the certificate and reinstalling, but nothing works. What can I do to fix it?
Did you mean Firefox? I tried that, butI still can't get to Google, Yahoo, etc. But I can get to Amazon, on Firefox only, nothing on the other browsers.
Hi,
yes, I meant firefox. IE needs the CA installed in its configuration.
Does your web -> general page look a bit like this?
Ian
XGS118 - v21.5.0
XG115 converted to software licence v21.5.0
If a post solves your question please use the 'Verify Answer' button.
OK. I did import the CA into IE as well, but it still won't allow me to go to Google, etc.
My web - general page does look exactly like that. I downloaded this CA from the System - Certificates - Certificate Authorities, and its the certificate I have been importing into the browsers.
Can you show us a screenshot of your GPO / certificate page?
__________________________________________________________________________________________________________________
I meant on the Client. And which did you import where?
__________________________________________________________________________________________________________________
SecurityAppliance_SSL_CA is the one I downloaded from the XG firewall and saved, then imported that into IE, FF, and Chrome.
IE:
Chrome:
FF:
Windows:
Perfect, and if you enable https scanning for this computer, can you show us the error?
__________________________________________________________________________________________________________________
Any ideas yet? I'm still trying to figure this out.
What about the certificate, when I download it from the XG, it is in the form of a .pem file. In Chrome for example, on the certificate import wizard, when browsing for the file to import, I have just been selecting the option to show all files, then I select that .pem file. The default is that it is looking for a .cer or .crt file. I didn't think it mattered, but do you think maybe it doesn't like the .pem file?
My experience with importing CAs is that if the application doesn't like the CA it will not install it eg want cert but gets pem.
Ian
XGS118 - v21.5.0
XG115 converted to software licence v21.5.0
If a post solves your question please use the 'Verify Answer' button.