This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"Blocked content" page not shown in Standard Mode if the site is HTTPS

Hello, 
I have noticed that if the Proxy Mode is Standard and you try to surf in a https site that should be blocked, the user does not see the Astaro Content Blocked page, but he see an error in the browser (see the screenshot). 

I have tried with https://www.facebook.com and https://imo.im.

Obviously I can surf in https web sites. I have tried both to enable and disable HTTPS scan.

This is the entry in the astaro log that shows the correct classification of the site:

2010:09:13-10:56:36 firewall httpproxy[20945]: id="0060" severity="info" sys="SecureWeb" sub="http" name="web request blocked, forbidden category detected" action="block" method="CONNECT" srcip="192.168.***.***" user="" statuscode="403" cached="0" profile="REF_kzFLrVCKWx (Profilo Guests)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2751" time="0 ms" request="0xb01b6928" url="imo.im/" exceptions="" error="" reason="category" category="106,122" reputation="neutral" categoryname="Chat,Instant Messaging"

Any idea?

Thank you


This thread was automatically locked due to age.
Parents
  • method="CONNECT"

    I think that means that any blocked https site will react the same way.  I don't know if this is desired behavior or a bug.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • method="CONNECT"

    I think that means that any blocked https site will react the same way.  I don't know if this is desired behavior or a bug.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • method="CONNECT"

    I think that means that any blocked https site will react the same way.  I don't know if this is desired behavior or a bug.

    Cheers - Bob


    Thank you Bob, 
    so do you obtain the same results? Did you try to get https://imo.im ?

    thanks [:D]
  • I didn't confirm other than by reading the log line you provided.  A little educated guessing:  you have 'Scan HTTPS (SSL) Traffic' checked, and the "man-in-the-middle" should have shown you the Astaro page instead of returning a 403.  Then again, maybe that would be considered a feature request.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA