If I bypass SSL decryption for a URL or list of URLs what happens in the ICAP rule? Do the bypassed URLs from the SSL ruleset still attempt to go to the ICAP server? Do I need to also exempt the URLs/List of URLs from the ICAP ruleset?
Solved! Go to Solution.
Hello,
basically if you bypass SSL Scanner all information MWG sees is the "CONNECT" request to establish the SSL connection, none of the requests of traffic within the tunnel.
MWG will send the CONNECT request to the ICAP server for filtering, if on the ICAP server there is a rule that blocks by URL the access can still be blocked.
Best,
Andre
Hello,
basically if you bypass SSL Scanner all information MWG sees is the "CONNECT" request to establish the SSL connection, none of the requests of traffic within the tunnel.
MWG will send the CONNECT request to the ICAP server for filtering, if on the ICAP server there is a rule that blocks by URL the access can still be blocked.
Best,
Andre
Hi,
Hope you are doing well.
Also to add generally it is not required sending all requests to ICAP server which is CONNECT/GET/POST etc which is not all required and is not per recommendation.
Only POST and PUT requests should be send to NDLP/ICAP. It will help your situation when limiting the types of requests that get sent over to DLP.
The only traffic that needs to go to NDLP is POST/PUT requests . Normal web requests (GET/CONNECT requests) need not be sent to DLP.
Command.Name can be used as a criteria here.
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: