I am using SSL decryption for all outbound traffic. Prior to the decryption rule I have a rule to attempt to exclude iTunes and App Store traffic from decryption. The rule seems to be working, but the App Store fails with "NSURLErrorDomain error -1012". When I turn off all decryption the App Store works. My rule is setup for no-decrypt from any source to the following addresses: albert.apple.com ax.init.itunes.apple.com ax.itunes.com deimos3.apple.com gs.apple.com guzzoni.apple.com itunes.apple.com p22-buy.itunes.apple.com phobos.apple.com se.itunes.apple.com su.itunes.apple.com I have URL filtering enabled, but everything is set to alert instead of block (excluding a few select categories like malware, online gambling, spam, phishing, etc). I also have a generic Trust->Untrust Accept security rule. Anybody have any ideas how to get this to work without excluding the source address from decryption?
... View more