<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Ravi, in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974869#M7002</link>
    <description>&lt;P&gt;Hi Ravi,&lt;/P&gt;
&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;It seems to be happening with all sites that I access under the .austfoot.com.au domain.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another example is &lt;A href="https://connx.austfoot.com.au" target="_blank"&gt;https://connx.austfoot.com.au&lt;/A&gt; as soon as I go through the WSA I get the SSL error.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2017 20:19:26 GMT</pubDate>
    <dc:creator>andrei.goutnik</dc:creator>
    <dc:date>2017-01-11T20:19:26Z</dc:date>
    <item>
      <title>https error on websites</title>
      <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974865#M6998</link>
      <description>&lt;P&gt;I am having an issue with Cisco Web Security Appliance (S380), accessing https websites.&lt;/P&gt;
&lt;P&gt;Specifically when trying to access our webmail website i get an error "ERR_SSL_PROTOCOL_ERROR" when running through the Cisco WSA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The website is &lt;A href="https://webmail.austfoot.com.au" target="_blank"&gt;https://webmail.austfoot.com.au&lt;/A&gt; we have a SSL certificate from DigiCert and i have added the *.austfoot.com.au domain to be bypassed in WSA however i still get the error.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Works fine if not going through the WSA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It used to work fine, however the Appliance was updated to the latest update and now it has stopped working. I thought i just needed to load the certificate into "Certificate Management" under trusted root, however that didnt work.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 22:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974865#M6998</guid>
      <dc:creator>andrei.goutnik</dc:creator>
      <dc:date>2017-01-09T22:35:42Z</dc:date>
    </item>
    <item>
      <title>Can you post some of the logs</title>
      <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974866#M6999</link>
      <description>&lt;P&gt;Can you post some of the logs from the access logs when the site is accessed?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2017 01:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974866#M6999</guid>
      <dc:creator>David Niemann</dc:creator>
      <dc:date>2017-01-10T01:45:45Z</dc:date>
    </item>
    <item>
      <title>Would it be the following?</title>
      <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974867#M7000</link>
      <description>&lt;P&gt;Would it be the following?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;1483928012.640 1 10.1.1.59 TCP_MISS/502 39 CONNECT tunnel://webmail.austfoot.com.au:443/ - DIRECT/webmail.austfoot.com.au - PASSTHRU_WEBCAT_7-DefaultGroup-AFL_Active_Directory-NONE-NONE-NONE-DefaultGroup &amp;lt;IW_sprt,0.0,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,IW_sprt,-,"-","-","Unknown","Unknown","-","-",312.00,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; -
1483928012.645 4 10.1.1.59 TCP_MISS/502 39 CONNECT tunnel://webmail.austfoot.com.au:443/ - DIRECT/webmail.austfoot.com.au - PASSTHRU_WEBCAT_7-DefaultGroup-AFL_Active_Directory-NONE-NONE-NONE-DefaultGroup &amp;lt;IW_sprt,0.0,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,IW_sprt,-,"-","-","Unknown","Unknown","-","-",78.00,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; -&lt;/PRE&gt;</description>
      <pubDate>Tue, 10 Jan 2017 06:05:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974867#M7000</guid>
      <dc:creator>andrei.goutnik</dc:creator>
      <dc:date>2017-01-10T06:05:44Z</dc:date>
    </item>
    <item>
      <title>You are getting this error</title>
      <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974868#M7001</link>
      <description>&lt;P&gt;You are getting this error only for this URL or whenever you are accessing any https site?&lt;/P&gt;
&lt;P&gt;In Some cases, SSL state may blok your connection and show you this error. Try to clear SSL state&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 15:25:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974868#M7001</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2017-01-11T15:25:29Z</dc:date>
    </item>
    <item>
      <title>Hi Ravi,</title>
      <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974869#M7002</link>
      <description>&lt;P&gt;Hi Ravi,&lt;/P&gt;
&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;It seems to be happening with all sites that I access under the .austfoot.com.au domain.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another example is &lt;A href="https://connx.austfoot.com.au" target="_blank"&gt;https://connx.austfoot.com.au&lt;/A&gt; as soon as I go through the WSA I get the SSL error.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 20:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/2974869#M7002</guid>
      <dc:creator>andrei.goutnik</dc:creator>
      <dc:date>2017-01-11T20:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: You are getting this error</title>
      <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/3943665#M8835</link>
      <description>&lt;P&gt;pertanyaan saya yang ingin saya tanyakan karena kasus yang saya alami hampir sama di ip menuju website &lt;A href="https://www.pekalongan-news.com/" target="_self"&gt;Pekalongan news&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2019 01:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/3943665#M8835</guid>
      <dc:creator>jonianggara65839</dc:creator>
      <dc:date>2019-10-19T01:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Would it be the following?</title>
      <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/4004609#M8920</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN class=""&gt;&lt;A id="link_13" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/107895" target="_self"&gt;andrei.goutnik&lt;/A&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;The domain you have mentioned is not being bypassed. I think you added ".austfoot.com.au" to the bypass settings on the WSA when you says you have bypassed it however you have an explicit setup ( either PAC file, Hostname/Ip of the WSA in the browser). Bypass settings on the WSA work only with the Transparent setup (wccp). Please bypass this domain on the PAC file or on the browser it self. you cannot bypass it on the WSA. you can try to make a custom url category also and allow /passthrough it in access/decryption policy and check if it works. If it doesn't then you have bypass it for sure.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Shikha Grover&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and select as validated answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 05:11:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/4004609#M8920</guid>
      <dc:creator>shgrover</dc:creator>
      <dc:date>2019-12-30T05:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: https error on websites</title>
      <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/4631158#M10136</link>
      <description>&lt;P&gt;I cant visit half of the &lt;A href="https://potteryandcrafting.com/best-pottery-wheels-for-beginners/" target="_self"&gt;website&lt;/A&gt;&amp;nbsp;on the internet. The connection is not sure on half of the websites. Anyone know the solution to this?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 23:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/4631158#M10136</guid>
      <dc:creator>jameslehner992</dc:creator>
      <dc:date>2022-06-13T23:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: https error on websites</title>
      <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/4632037#M10141</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1366503"&gt;@jameslehner992&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;kindly share with us more details about your issue.&lt;/P&gt;
&lt;P&gt;you can brows some https and can not brose some https site ( approximately 50%-50%)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if so please share the output of sslconfig &amp;gt; versions from CLI and some lines of access logs from blocked URLs and allowed URLs&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 20:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/4632037#M10141</guid>
      <dc:creator>amojarra</dc:creator>
      <dc:date>2022-06-14T20:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: Would it be the following?</title>
      <link>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/4632042#M10142</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/107895"&gt;@andrei.goutnik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see HTTP 502 from your accesslog which is Bad gateway.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you done the steps&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/137215"&gt;@shgrover&lt;/a&gt;&amp;nbsp; mentioned and still get 502 from accesslogs,&amp;nbsp;could you please capture packet from WSA filter for your client IP and your server IP , try to reproduce the issue and share the PCAP.&lt;/P&gt;
&lt;P&gt;to do this check page 569 userguide :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa_14-0/User-Guide/b_WSA_UserGuide_14_0.pdf" target="_blank"&gt;User Guide for AsyncOS 14.0 for Cisco Web Security Appliances - GD (General Deployment)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly note that I can not open the URL :&amp;nbsp;&lt;A href="https://webmail.austfoot.com.au/" target="_blank"&gt;https://webmail.austfoot.com.au&lt;/A&gt;&amp;nbsp;from my computer and I get :&amp;nbsp;&lt;SPAN&gt;ERR_CONNECTION_TIMED_OUT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;also I can not resolve&amp;nbsp;austfoot.com.au&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 20:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-error-on-websites/m-p/4632042#M10142</guid>
      <dc:creator>amojarra</dc:creator>
      <dc:date>2022-06-14T20:47:27Z</dc:date>
    </item>
  </channel>
</rss>

