IT_Man_Dan Posted June 27, 2024 Posted June 27, 2024 Afternoon all, We've setup a guest wifi and have it going through its own NIC on the smoothwall. Is there any easy way to set it so that any HTTPS traffic on that NIC is not set to Decrypt and inspect so that users don't need to install the certificate? We've tried setting a policy in the HTTPS inspection policy area but it doesn't seem to work. Many thanks
DGardiner Posted June 27, 2024 Posted June 27, 2024 Afternoon all, We've setup a guest wifi and have it going through its own NIC on the smoothwall. Is there any easy way to set it so that any HTTPS traffic on that NIC is not set to Decrypt and inspect so that users don't need to install the certificate? We've tried setting a policy in the HTTPS inspection policy area but it doesn't seem to work. Many thanks you could create a location with the ip range of the stuff on that nic, dont think you can turn off based on where it goes in
ThomL Posted June 27, 2024 Posted June 27, 2024 We have this config at the moment, using a location for the guest WiFi - location is the subnet used by the guest WiFi:
Primus Posted June 27, 2024 Posted June 27, 2024 Afternoon all, We've setup a guest wifi and have it going through its own NIC on the smoothwall. Is there any easy way to set it so that any HTTPS traffic on that NIC is not set to Decrypt and inspect so that users don't need to install the certificate? We've tried setting a policy in the HTTPS inspection policy area but it doesn't seem to work. Many thanks Just a quick reminder - have you risk assessed this as it does blind you to a lot of traffic now. 1
IT_Man_Dan Posted June 27, 2024 Author Posted June 27, 2024 (edited) We have pretty much set this the same but it isn't working for us. What have you got in your transparent proxy settings for the guest wifi please @ThomL Edited June 27, 2024 by IT_Man_Dan
ThomL Posted June 27, 2024 Posted June 27, 2024 Transparent setting: Web filter policies: This might be the part you're missing? The unauthed requests being assigned to a group in the transparent polices and then allowing all traffic from that group on the web filter side?
tom_newton Posted June 27, 2024 Posted June 27, 2024 You can create a "location" for that IP range... or as someone said create a default user group for that proxy, and then exempt those from https inspection
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now