Type=Deny while Action=Allow

L2 Linker

Type=Deny while Action=Allow

When opening iOS Facebook app I''m unable to play a movie... however, from the same device if I login to facbook via browser I can play the video.

I'm trying to find out why the iOS App is getting blocked, as my policies clearly allow it.

Rule iPhones:

 iPhone Policy.JPGIphone Rule allowing all traffic



Traffic Allowed.JPGLog when using Facebook via Chrome



Blocked Traffic.JPGLog when using Facebook via iOS App



Decryption Policy.JPGDecryption Policy


 I'm not sure what I'm missing here. I'm trying to understand what is causing the traffic to be blocked. The only thing I see different is the fact that when the user is using the App PA shows the traffic as SSL and when using the Chrome PA shows it as facebook-Video. However, both should be allowed.


Any ideas? I'm running VM-100 on 7.1.9.





L2 Linker

Re: Type=Deny while Action=Allow

For what is worth, I went to Device tab > Response Pages screen, I unticked the "Enable SSL Opt-out Page" option. After that, it looks like it is working.

Opt Out Response Page.JPGResponse Page

So I believe the page was sent to the app and it was timing out as there would beno reply. Not exacly what I was execting, but that is the only explanation on my mind. 


UPATE: problem still presists. VIdeo must have been cached when I was testing it.

L2 Linker

Re: Type=Deny while Action=Allow

I saw the same behavior. When I ran a packet capture on the traffic, I noticed the client was unable to validate the certificate and closed the connection. The traffic had to be exempted as I couldn't include the Decryption CA root in the application's trusted certificate store.

L2 Linker

Re: Type=Deny while Action=Allow

In my case the application was not identified when using the Facebook App (shows just SSL). Interesting enough, when using Chrome one the iPhone, it identifies it as Facebook-Video. So I had to create a rule to exempt any Social-Network category for iPhones, which isn't ideal, but it was the lowest denominator. Otherwise I have to exclude iPhone from decryption all together or at least iPhones SSL.
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!