SSL/TLS filtering must have extension server_name
Options
PeterUK
Posts: 4,268
Guru Member
Guru Member
For Content Filter the SSL/TLS traffic must have extension server_name or else block option.

1
Comments
-
I think the "Trusted Web Sites" , "Forbidden Web Sites" also use SNI (Server Name filed) to identify.
So it should work.

0 -
I don't think you get what I mean I want to allow all SSL/TLS traffic but drop traffic without extension server_name because the USG can't know what its for.
0
Categories
- All Categories
- 441 Beta Program
- 2.9K Nebula
- 208 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 528 USG FLEX H Series
- 331 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 50 Wireless Ideas
- 6.9K Consumer Product
- 293 Service & License
- 462 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.7K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight
Master Member