- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-07-2019 09:46 PM
Hi Everyone,
IP 13.57.194.193 ssl decryption exempt was failing and I
In ssl decrypt exclusion list I put *.amazonaws.com and still in traffic logs I see the IP 13.57.194.193 getting ssl decrypted.
I have attached the nslookup for this ip.
Can you please tell me how we can config ssl decrypt exclusion for below hostname?
11-09-2019 06:21 AM
@MP18, that is the thing.
You are attempting to configure the FW for something that the feature was not designed for.
We do NOT use the SSL exclusion for what you are attempting to do.
The exclusion list is for technical difficulties with pinned certs, client side authentication, etc.
The issue with Amazon is proprietary certs, which does not all into this category/reasoning.
11-08-2019 06:35 AM
Create a new "WorkAround" custom URL Category and put in all sites that you do NOT want to be decrypted.
11-08-2019 10:46 AM
Thanks for replying.
Custom url category i know.
I was wondering how can be do this in ssl decrypt exclusion list?
11-09-2019 06:21 AM
@MP18, that is the thing.
You are attempting to configure the FW for something that the feature was not designed for.
We do NOT use the SSL exclusion for what you are attempting to do.
The exclusion list is for technical difficulties with pinned certs, client side authentication, etc.
The issue with Amazon is proprietary certs, which does not all into this category/reasoning.
11-09-2019 10:02 AM
That is good to know.
this is first time I learned about this.
Thanks for helping me out on this
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!