GP on Android 9, SSL decryption and exclude local private network problem.

cancel
Showing results for 
Search instead for 
Did you mean: 

GP on Android 9, SSL decryption and exclude local private network problem.

L0 Member

Hello, 

 

i have been messing about with GP in combination with Android 9. I've imported the certificate setup the right decryption rules and exclusions etc. and things seem to working. When i check the certificate using Chrome i can confirm it is using ssl decryption i also see the traffic on our firewall. Onfortunately a lot of application are not working. I've got the google play store excluded from ssl decryption already and that seems to be working fine, but still a lot of applications are not ok with the ssl decryption so it seems. My Ssl decryption setup using a laptop is working fine btw. 

 

Is this normal on androids? is android working with more cert stores ? there something i can do to make this work without excluding all these applications?

 

Another thing i came across is that the network exclusion for my local private network is not working, i see the request coming in on the firewall. When testing this config on my laptop win 10, it is working... is this by design?

 

thanks guys. 

 

regards, Lennart

 

 

2 REPLIES 2

Cyber Elite
Cyber Elite

@hmcadmin,

This is to be expected. A lot of Android applications will use their own certificate store for validation, so a lot of applications will break if not properly excluded. You just have to kind of deal with these as they come up.

Hi hmcadmin,

 

Android does not support exclude access route split tunneling.

 

Regards,

Varun

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!