We are using a Firewall with a web filtering service. It has also SSL inspection function.
Does MWG need to install the certificate of that firewall if SSL inspection is enabled on the FIrewall? does the endpoint machines still need to install the cerificate of the Firewall?
Solved! Go to Solution.
Hi,
Hope you are doing well.
Yes this can be done via GUI.
Inside SSL Scanner-> Certificate Verification-> Skip Verification for Certificates Found in Certificate Whitelist-> You can whitelist the certificate here.
Alternatively also When you have SSL Scanner rule set enabled in MWG , for certificate verification we have by default a profile present in which you can have a your own list of certificate authority configured and also have a mcafee maintained known CA list.
In your scenario this mcafee maintained list is not required.
You can take MWG GUI access-> Navigate to option Settings-> Certificate Chain->Default-> List of certificate authorities-> Their you can configure and import firewall certificate for MWG to trust
Regards
Alok Sarda
Hi,
Hope you are doing well.
Client->MWG->Firewall
Firewall is doing web filtering service. It has also SSL inspection function.
Above is the setup, correct me if I am wrong.
If SSL Scanner is not enabled on MWG, then MWG does not need to install the certificate of that firewall. Yes endpoint machines still need to install the certificate of the Firewall in order to trust.
If SSL Scanning is also enabled on MWG, then yes on MWG you need to install certificate of the firewall to trust it. On endpoint machines you need to import the root certificate of the certificate being used for SSL Scanning in MWG.
Was my reply helpful? If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Regards
Alok Sarda
Hi @aloksard ,
how do you install the certificate of firewall on MWG? will it be using the GUI of the MWG?
Hi,
Hope you are doing well.
Yes this can be done via GUI.
Inside SSL Scanner-> Certificate Verification-> Skip Verification for Certificates Found in Certificate Whitelist-> You can whitelist the certificate here.
Alternatively also When you have SSL Scanner rule set enabled in MWG , for certificate verification we have by default a profile present in which you can have a your own list of certificate authority configured and also have a mcafee maintained known CA list.
In your scenario this mcafee maintained list is not required.
You can take MWG GUI access-> Navigate to option Settings-> Certificate Chain->Default-> List of certificate authorities-> Their you can configure and import firewall certificate for MWG to trust
Regards
Alok Sarda
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: