SSL/TLS filtering must have extension server_name
Options
PeterUK
Posts: 4,167
Guru Member
Guru Member
For Content Filter the SSL/TLS traffic must have extension server_name or else block option.

1
Comments
-
I think the "Trusted Web Sites" , "Forbidden Web Sites" also use SNI (Server Name filed) to identify.
So it should work.

0 -
I don't think you get what I mean I want to allow all SSL/TLS traffic but drop traffic without extension server_name because the USG can't know what its for.
0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 200 Nebula Ideas
- 126 Nebula Status and Incidents
- 6.3K Security
- 497 USG FLEX H Series
- 323 Security Ideas
- 1.6K Switch
- 83 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.8K Consumer Product
- 286 Service & License
- 457 News and Release
- 89 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 95 Security Highlight
Master Member