This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Filtering with URL Only

Hi!

 

I am testing Sophos UTM in a VM, before buying the hardware to run it. I already used before Sophos UTM for a customer having SG230s. So, Everything is working fine, I got my IPS, firewall, NAT, etc.. Arrived to the web filter. I did a default rule then set HTTPS to url only. No SSL Inspection/scanning.

 

THe problem, everytimes I test a blocked website, my AV always telling me that there is an untrusted certificate, which is the UTM Proxy CA.

 

Is there a way, (without having to import the certificate) to have only URL filtering? I remember that I I can do this on some other brand firewall, and I remember that when I used it for a customer, there was no problem with the certificate. The thing is that my computers are not in a domain, or when mobile device or guest device are connected, I don't want them to see any certificate error, just get the website blocked by URL filtering.

 

Thanks



This thread was automatically locked due to age.
Parents
  • Thanks for the reply. I thought maybe the UTM was able to do SNI (server name indication) before the certificate is queried between browser and web server.

    Or any blacklist using categories before, as a workaround.

    Thanks again. I could maybe use open dns for that kind of block. The utm is doing very fine for all the other options, i am happy of it

  • Please be aware that UTM filters on whatever portion of the URL it is able to see.   For http websites, and for https websites with inspection enabled, different portions of a website may be assigned to different categories.

    If DNS block is implemented as a NXDOMAIN result (no IP address), the block will be detected immediately. 

    However, if the DNS block is implemented as a redirect to a block message, you will have the certificate problem all over again, when the requested URL uses https protocol.

     

Reply
  • Please be aware that UTM filters on whatever portion of the URL it is able to see.   For http websites, and for https websites with inspection enabled, different portions of a website may be assigned to different categories.

    If DNS block is implemented as a NXDOMAIN result (no IP address), the block will be detected immediately. 

    However, if the DNS block is implemented as a redirect to a block message, you will have the certificate problem all over again, when the requested URL uses https protocol.

     

Children
No Data