cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
clath13
Level 9
Report Inappropriate Content
Message 1 of 3

SSL decryption and ICAP

Jump to solution

If I bypass SSL decryption for a URL  or list of URLs what happens in the ICAP rule?  Do the bypassed URLs from the SSL ruleset still attempt to go to the ICAP server?  Do I need to also exempt the URLs/List of URLs from the ICAP ruleset?

1 Solution

Accepted Solutions
asabban
Employee
Employee
Report Inappropriate Content
Message 2 of 3

Re: SSL decryption and ICAP

Jump to solution

Hello,

basically if you bypass SSL Scanner all information MWG sees is the "CONNECT" request to establish the SSL connection, none of the requests of traffic within the tunnel.

MWG will send the CONNECT request to the ICAP server for filtering, if on the ICAP server there is a rule that blocks by URL the access can still be blocked.

Best,
Andre

View solution in original post

2 Replies
asabban
Employee
Employee
Report Inappropriate Content
Message 2 of 3

Re: SSL decryption and ICAP

Jump to solution

Hello,

basically if you bypass SSL Scanner all information MWG sees is the "CONNECT" request to establish the SSL connection, none of the requests of traffic within the tunnel.

MWG will send the CONNECT request to the ICAP server for filtering, if on the ICAP server there is a rule that blocks by URL the access can still be blocked.

Best,
Andre

aloksard
Employee
Employee
Report Inappropriate Content
Message 3 of 3

Re: SSL decryption and ICAP

Jump to solution

Hi,

 

Hope you are doing well.

 

Also to add generally it is not required sending all requests to ICAP server which is CONNECT/GET/POST etc which is not all required and is not per recommendation.


Only POST and PUT requests should be send to NDLP/ICAP. It will help your situation when limiting the types of requests that get sent over to DLP. 


The only traffic that needs to go to NDLP is POST/PUT requests . Normal web requests (GET/CONNECT requests) need not be sent to DLP.

 

Command.Name can be used as a criteria here.

 

Was my reply helpful? If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
 
 
Regards
Alok Sarda
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community