Type=Deny while Action=Allow

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Type=Deny while Action=Allow

L2 Linker

When opening iOS Facebook app I''m unable to play a movie... however, from the same device if I login to facbook via browser I can play the video.

I'm trying to find out why the iOS App is getting blocked, as my policies clearly allow it.

Rule iPhones:

 Iphone Rule allowing all trafficIphone Rule allowing all traffic

 

 

Log when using Facebook  via ChromeLog when using Facebook via Chrome

 

 

Log when using Facebook via iOS AppLog when using Facebook via iOS App

 

 

Decryption PolicyDecryption Policy

 

 I'm not sure what I'm missing here. I'm trying to understand what is causing the traffic to be blocked. The only thing I see different is the fact that when the user is using the App PA shows the traffic as SSL and when using the Chrome PA shows it as facebook-Video. However, both should be allowed.

 

Any ideas? I'm running VM-100 on 7.1.9.

 

Thanks!

 

 

1 accepted solution

Accepted Solutions

I saw the same behavior. When I ran a packet capture on the traffic, I noticed the client was unable to validate the certificate and closed the connection. The traffic had to be exempted as I couldn't include the Decryption CA root in the application's trusted certificate store.

View solution in original post

4 REPLIES 4

L2 Linker

For what is worth, I went to Device tab > Response Pages screen, I unticked the "Enable SSL Opt-out Page" option. After that, it looks like it is working.

Response PageResponse Page

So I believe the page was sent to the app and it was timing out as there would beno reply. Not exacly what I was execting, but that is the only explanation on my mind. 

 

UPATE: problem still presists. VIdeo must have been cached when I was testing it.

I saw the same behavior. When I ran a packet capture on the traffic, I noticed the client was unable to validate the certificate and closed the connection. The traffic had to be exempted as I couldn't include the Decryption CA root in the application's trusted certificate store.

In my case the application was not identified when using the Facebook App (shows just SSL). Interesting enough, when using Chrome one the iPhone, it identifies it as Facebook-Video. So I had to create a rule to exempt any Social-Network category for iPhones, which isn't ideal, but it was the lowest denominator. Otherwise I have to exclude iPhone from decryption all together or at least iPhones SSL.

How did you exempt the traffic? The rule looks like it should have exempted it already. Do you mean you do not decrypt?

  • 1 accepted solution
  • 16287 Views
  • 4 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!