<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Web Server with HTTPS encryption showing different responses from both internal and external network</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/133574/web-server-with-https-encryption-showing-different-responses-from-both-internal-and-external-network</link><description>We have a new SSL certificate installed in Sophos for a website we are hosting. When I configure the web server with an HTTP encryption, there is no issue. But when I change it to HTTPS encryption, these are the issues we are having: 
 From internal network</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Web Server with HTTPS encryption showing different responses from both internal and external network</title><link>https://community.sophos.com/thread/492378?ContentTypeID=1</link><pubDate>Thu, 31 Mar 2022 02:34:57 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0778c8a5-fefd-48a5-af9c-b0e429034039</guid><dc:creator>Jason Roble</dc:creator><description>&lt;p&gt;Got it. Thank you for the clarification &lt;a href="/members/prism"&gt;Prism&lt;/a&gt;! &lt;span class="emoticon" data-url="https://community.sophos.com/cfs-file/__key/system/emoji/1f642.svg" title="Slight smile"&gt;&amp;#x1f642;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Web Server with HTTPS encryption showing different responses from both internal and external network</title><link>https://community.sophos.com/thread/492186?ContentTypeID=1</link><pubDate>Tue, 29 Mar 2022 11:32:05 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:447ccc6f-82d2-4bfa-bcb0-af9c97482354</guid><dc:creator>Prism</dc:creator><description>&lt;p&gt;It highly depends on how your current network is configured, and on what compliance&amp;#39;s you need to meet.&lt;/p&gt;
&lt;p&gt;It&amp;#39;s common to have a WAF terminating TLS on the edge then transmitting data through plain-text for higher performance (and caching on some other scenarios), but depending on how your internal network is currently&amp;nbsp;configured this can be either insecure or secure.&lt;/p&gt;
&lt;p&gt;The important part for you is having a secure connection between the client and the WAF.&lt;/p&gt;
&lt;p&gt;PS; If the connection from the WAF to the Web Server is encrypted through HTTPS, the IPS will have no effect as It can&amp;#39;t inspect the encrypted data, making It useless.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Web Server with HTTPS encryption showing different responses from both internal and external network</title><link>https://community.sophos.com/thread/492184?ContentTypeID=1</link><pubDate>Tue, 29 Mar 2022 10:48:38 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f00fcc7d-2a85-4d54-8bca-b6cce808232a</guid><dc:creator>Jason Roble</dc:creator><description>&lt;p&gt;Regarding the downstream web server, I am not sure but I guess it doesn&amp;#39;t support HTTPS.&lt;/p&gt;
&lt;p&gt;So as long as the WAF&amp;#39;s encryption method is HTTPS, the Web Server&amp;#39;s encryption type is insignificant if the server is internal? I thought I need to make both WAF and Web Server&amp;#39;s encryption method to be HTTPS to make it secured.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Web Server with HTTPS encryption showing different responses from both internal and external network</title><link>https://community.sophos.com/thread/492167?ContentTypeID=1</link><pubDate>Tue, 29 Mar 2022 03:40:56 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:44bc0cb0-40a0-4b5c-b1d3-e89ef4f5ed30</guid><dc:creator>Prism</dc:creator><description>&lt;p&gt;Does the downstream Web Server&amp;nbsp;(IP_DMZ_CSI-SVR03) also supports HTTPS?&lt;/p&gt;
&lt;p&gt;Looking by the error given by WAF, the downstream Web Server is only available through plain-text HTTP.&lt;/p&gt;
&lt;p&gt;I recommend you to change from HTTPS to HTTP on the Web Server configuration. (Maintaining the same port 8080.)&lt;/p&gt;
[quote userid="236961" url="~/sophos-xg-firewall/f/discussions/133574/web-server-with-https-encryption-showing-different-responses-from-both-internal-and-external-network"]When I configure the web server with an HTTP encryption, there is no issue. But when I change it to HTTPS encryption, these are the issues we are having:[/quote]
&lt;p&gt;It&amp;#39;s because the downstream Web Server (IP_DMZ_CSI-SVR03) doesn&amp;#39;t support HTTPS.&lt;/p&gt;
&lt;p&gt;You should leave the WAF to handle the encryption with the client and send the traffic to downstream though plain-text HTTP. (There&amp;#39;s no need for the WAF to encrypt all traffic again with downstream, unless you don&amp;#39;t trust your own internal network.)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Web Server with HTTPS encryption showing different responses from both internal and external network</title><link>https://community.sophos.com/thread/492165?ContentTypeID=1</link><pubDate>Tue, 29 Mar 2022 03:07:07 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5b9f48b4-74b0-44c4-8eb1-cfaba063013a</guid><dc:creator>Jason Roble</dc:creator><description>&lt;p&gt;Yes this is about WAF. This is the WAF configuration&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1648523142456v1.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;and this is the Web Server config&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1648523184261v2.png" alt=" " /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Web Server with HTTPS encryption showing different responses from both internal and external network</title><link>https://community.sophos.com/thread/492118?ContentTypeID=1</link><pubDate>Mon, 28 Mar 2022 15:31:09 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:74f57e92-7443-4385-b889-da0f10fc4160</guid><dc:creator>PhilippRusch</dc:creator><description>&lt;p&gt;Are we talking about WAF here?&lt;/p&gt;
&lt;p&gt;Can you show us your rules?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Web Server with HTTPS encryption showing different responses from both internal and external network</title><link>https://community.sophos.com/thread/492093?ContentTypeID=1</link><pubDate>Mon, 28 Mar 2022 12:23:19 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1be71bb7-0c52-4a79-aed6-a958e0b905db</guid><dc:creator>Jason Roble</dc:creator><description>&lt;p&gt;Yes it has a green check on the Trusted column.&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1648470169167v2.png" alt=" " /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Web Server with HTTPS encryption showing different responses from both internal and external network</title><link>https://community.sophos.com/thread/492087?ContentTypeID=1</link><pubDate>Mon, 28 Mar 2022 11:39:46 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:62c43981-5ba6-4e4e-9f25-d456be3fbb3e</guid><dc:creator>PhilippRusch</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;is this new certificate showing up as &amp;quot;trusted&amp;quot; under Certificates in the Sophos System?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>