Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

TLS decryption issue explanation for beginner

Hello,

I am converting our customers from primitive FWs to Sophos XGS's and testing TLS decryption.

Would anyone be so kind to walk me through what is happening in specific case below:

Setup: TLS enabled, any of default profiles, Sophos CA as trusted on client computer.

Website: https://www.pentahospitals.cz/  (Czech private hospital group)

Error in logs: Blocked due to invalid TLS certificate

What is the reall cause for the error here? Does this mean that I need to exclude possible loads of websites with similar configurations?

Thank You!



Added TAGs
[edited by: Raphael Alganes at 2:26 PM (GMT -7) on 1 Nov 2024]
Parents Reply Children