This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL/TLS Exception for Anydesk

Hi,

I try to get anydesk running with TLS Inspection. I´ve read this post: https://community.sophos.com/sophos-xg-firewall/f/discussions/123967/how-to-allow-or-block-anydesk-when-using-tls-scanning

I created a IP List with all the anydesk Servers, but where can I define the exception?

Thanks



This thread was automatically locked due to age.
Parents
  • Unfortunately https://community.sophos.com/sophos-xg-firewall/f/discussions/123967/how-to-allow-or-block-anydesk-when-using-tls-scanning is now locked, which is why you will have had to create a new post here.

    If those providing answers read the original post, they will see this is nothing to do with URLs. Anydesk uses IP connections, not URLs for the remote access sessions, hence the need to create an IP list and exempt that from scanning, which is what the OP was asking about.

    I'm glad you figured out how to do it . For those coming across this post as a search result, here is the rule I use (pick 'Rule and Policies' on the left, then the 'SSL/TLS inspection rules' on the top tab). It's very standard stuff, which is why I didn't put it in the original post, but if you aren't used to setting up Exceptions, I can understand struggling to find it.

    Unfortunately, Anydesk seem to regularly add to this list (currently about 400 IPs) so it needs updating quite often. Would be nice if Sophos could just make inspection work with Anydesk.

Reply
  • Unfortunately https://community.sophos.com/sophos-xg-firewall/f/discussions/123967/how-to-allow-or-block-anydesk-when-using-tls-scanning is now locked, which is why you will have had to create a new post here.

    If those providing answers read the original post, they will see this is nothing to do with URLs. Anydesk uses IP connections, not URLs for the remote access sessions, hence the need to create an IP list and exempt that from scanning, which is what the OP was asking about.

    I'm glad you figured out how to do it . For those coming across this post as a search result, here is the rule I use (pick 'Rule and Policies' on the left, then the 'SSL/TLS inspection rules' on the top tab). It's very standard stuff, which is why I didn't put it in the original post, but if you aren't used to setting up Exceptions, I can understand struggling to find it.

    Unfortunately, Anydesk seem to regularly add to this list (currently about 400 IPs) so it needs updating quite often. Would be nice if Sophos could just make inspection work with Anydesk.

Children