This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Filtering with URL Only

Hi!

 

I am testing Sophos UTM in a VM, before buying the hardware to run it. I already used before Sophos UTM for a customer having SG230s. So, Everything is working fine, I got my IPS, firewall, NAT, etc.. Arrived to the web filter. I did a default rule then set HTTPS to url only. No SSL Inspection/scanning.

 

THe problem, everytimes I test a blocked website, my AV always telling me that there is an untrusted certificate, which is the UTM Proxy CA.

 

Is there a way, (without having to import the certificate) to have only URL filtering? I remember that I I can do this on some other brand firewall, and I remember that when I used it for a customer, there was no problem with the certificate. The thing is that my computers are not in a domain, or when mobile device or guest device are connected, I don't want them to see any certificate error, just get the website blocked by URL filtering.

 

Thanks



This thread was automatically locked due to age.
Parents
  • When the UTM blocks, it wants to display a block page to tell the user what it is doing and why.  Therefore it must do man-in-the-middle and sign the block page with its own certificate.

    The XG product has another option, that if HTTPS scanning is off and the request should be blocked that it just drops the connection.  That way the browser will not get an error about certificates, however it may display errors about "cannot connect".

     

Reply
  • When the UTM blocks, it wants to display a block page to tell the user what it is doing and why.  Therefore it must do man-in-the-middle and sign the block page with its own certificate.

    The XG product has another option, that if HTTPS scanning is off and the request should be blocked that it just drops the connection.  That way the browser will not get an error about certificates, however it may display errors about "cannot connect".

     

Children
No Data