Jump to content

Recommended Posts

Posted

Afternoon all,

 

We've setup a guest wifi and have it going through its own NIC on the smoothwall. Is there any easy way to set it so that any HTTPS traffic on that NIC is not set to Decrypt and inspect so that users don't need to install the certificate?

We've tried setting a policy in the HTTPS inspection policy area but it doesn't seem to work.

 

Many thanks

Posted
Afternoon all,

 

We've setup a guest wifi and have it going through its own NIC on the smoothwall. Is there any easy way to set it so that any HTTPS traffic on that NIC is not set to Decrypt and inspect so that users don't need to install the certificate?

We've tried setting a policy in the HTTPS inspection policy area but it doesn't seem to work.

 

Many thanks

 

 

you could create a location with the ip range of the stuff on that nic, dont think you can turn off based on where it goes in

Posted

We have this config at the moment, using a location for the guest WiFi - location is the subnet used by the guest WiFi:

HTTPS-Guest-WiFi.png

Posted
Afternoon all,

 

We've setup a guest wifi and have it going through its own NIC on the smoothwall. Is there any easy way to set it so that any HTTPS traffic on that NIC is not set to Decrypt and inspect so that users don't need to install the certificate?

We've tried setting a policy in the HTTPS inspection policy area but it doesn't seem to work.

 

Many thanks

 

Just a quick reminder - have you risk assessed this as it does blind you to a lot of traffic now.

  • Thanks 1
Posted (edited)
We have pretty much set this the same but it isn't working for us. What have you got in your transparent proxy settings for the guest wifi please @ThomL Edited by IT_Man_Dan
Posted

Transparent setting:

transparent-Guest-WiFi.png

 

Web filter policies:

Webfilter-Pol-Guest-WiFi.png

 

This might be the part you're missing? The unauthed requests being assigned to a group in the transparent polices and then allowing all traffic from that group on the web filter side?

Posted
You can create a "location" for that IP range... or as someone said create a default user group for that proxy, and then exempt those from https inspection

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...