Cisco Cisco Web Security Appliance S670 Betriebsanweisung

Seite von 606
 
11-22
Cisco IronPort AsyncOS 7.7 for Web User Guide
Chapter 11      Processing HTTPS Traffic
Bypassing Decryption for Particular Websites
For example, note that a web reputation score drop action overrides any action defined for predefined 
URL categories.
Note
The configured default action only affects the action on the HTTPS request when web reputation 
filtering is not enabled, or when it is enabled and the server has no score assigned and the action for 
servers with no scores is to Monitor.
Bypassing Decryption for Particular Websites
Some HTTPS servers do not work as expected when traffic to them is decrypted by a proxy server, such 
as the Web Proxy. For example, some websites and their associated web applications and applets, such 
as high security banking sites, maintain a hard-coded list of trusted certificates instead of relying on the 
operating system certificate store.
You can bypass decryption for HTTPS traffic to these servers to ensure all users can access these types 
of sites. 
Step 1
Create a custom URL category that contains the affected HTTPS servers by configuring the Advanced 
properties.
Step 2
Create a Decryption Policy that uses the custom URL category created in 
 as part of its 
membership, and set the action for the custom URL category to Pass Through.
Trusted Root Certificates
The Web Security appliance ships with and maintains a list of trusted root certificates. Web sites with 
trusted certificates do not require decryption. 
You can manage the trusted certificate list, adding certificates to it and functionally removing certificates 
from it. While the Web Security appliance does not delete certificates from the master list, it allows you 
to override trust in a certificate, which functionally removes the certificate from the trusted list. 
Adding Certificates to the Trusted List
Before you begin
  •
Verify that the HTTPS Proxy is enabled. 
Step 1
Select Security Services HTTPS Proxy.
Step 2
Click Manage Trusted Root Certificates.
Step 3
Click Import.
Step 4
Click Browse and navigate to the certificate file.
Step 5
Submit and Commit your changes. 
Look for the certificate you uploaded in the Custom Trusted Root Certificates list.