For BYOD we are not planning on forcing users to download the Sophos Cert, we are not performing any HTTPS packet inspection on our wireless networks so users should just be able to connect and browse. This appears to be working without issues apart from one thing.
We are still blocking some categories such as gambling, pornography etc. These sites are being blocked successfully, however instead of displaying the block page, it just comes up a certificate error. Is thee any way of getting the block page to show without having the Sophos Cert installed on the end user devices?
This is not a problem for our corporate network since we have the Sophos Cert pushed out via GPO, so everything displays correctly.
Hi David Ashcroft
Could you please share the screenshot of the message you are getting?
Regards,
Keyur
Community Support Engineer | Sophos Support
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question use the 'This helped me' link
Hi David Ashcroft,
If you are blocking a category such as Gambling and a user goes to https://www.pokerstars.com/ then you want that web request to be blocked. The web proxy sees that the client is trying to go somewhere they should not and wants to display a block page. In order to do so, they need to do man-in-the-middle decryption so that it can insert a block page that pretends to be www.pokerstars.com.
Check out this KBA for more detail : HTTPS Decrypt and Scan FAQ.
Thanks,
This does make sense, I think this is why we are receiving the the block page correctly on our corporate network - because we have pushed out the Sophos MITM cert.
However, I was wondering if there is a way around this for our wireless network. We get about 2.5k users connecting to our WiFi network and we would prefer to have them not download our cert. Can Sophos redirect the traffic to a standard block page or something and display it as HTTP instead of HTTPS?
Thanks
Hi David Ashcroft,
Unfortunately, there is no way around it and display the block page as HTTP instead of HTTPS.
Thanks,
Maybe purchase a Webadmin Certificate with a public signed certificate.
Not for the HTTPs decryption (not possible), but for the blockpage etc.
__________________________________________________________________________________________________________________