kennysarmy Posted September 26, 2023 Posted September 26, 2023 Our staff have to accept a weekly HTTPS Interception warning message generated by the on-prem Smoothwall. I've a custom category called Bromcom which is set to Do Not Inspect. I thought this would allow Bromcom to function even if the weekly message was ignored. We're getting issues with Bromcom not displaying correctly until the message is checked off. The URL's in our Bromcom category are: bam.nr-data.net bi bidfooddirect.co.uk bootstrapcdn.com bromcom.com bromcomvle.com cdn.walkme.com cloudflare.com cloudmis.bromcom.com getbeamer.com googleapis.com highcharts.com jquery.com js-agent.newrelic.com microsoft.com microsoftonline.com mouseflow.com mychildatschool.com newrelic.com nr-data.net services.bromcom.com vision.bromcom.com vivomiles.com walkme.com Does anyone know of any other URL's I need for the above to work?
ibpalle Posted September 26, 2023 Posted September 26, 2023 Hi kennysarmy I would recommend disabling the warning - too many system apps, background apps etc are using https so the risk of not actually seeing the warning is fairly high and can then cause access issues in general. The best option for finding out what needs to be added is to test access to the Bromcom system from a known IP and then use the realtime web filter logs to monitor traffic from that IP and see what domains are accessed - any that are recognised by the category will list the category in the category field, any that are not in there will not, so add those o the Bromcom category.
kennysarmy Posted September 27, 2023 Author Posted September 27, 2023 Hi kennysarmy I would recommend disabling the warning - too many system apps, background apps etc are using https so the risk of not actually seeing the warning is fairly high and can then cause access issues in general. The best option for finding out what needs to be added is to test access to the Bromcom system from a known IP and then use the realtime web filter logs to monitor traffic from that IP and see what domains are accessed - any that are recognised by the category will list the category in the category field, any that are not in there will not, so add those o the Bromcom category. Thanks - now disabled.
ibpalle Posted September 27, 2023 Posted September 27, 2023 Just a bit of background. The warning was included as we were not quite certain about the legality of performing HTTPS inspection on user traffic. There were no precedent at the time and obviously Smoothwall is used in many different countries with different laws. It was fine initially when HTTPS was something that wasn't used widely but as everyone and their grandmother now use HTTPS for apps, sites and software the method of showing a warning in this manner isn't really fit for purpose.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now