<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA with Firepower SSL inspection problem for some https website in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978793#M1019745</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now, i am testing ASA firepower SSL inspection with 6.0. I configured CA as FSMC, SSL policy, Access control rules. Then i can go to &lt;EM&gt;&lt;A href="https://www.google.com" target="_blank"&gt;https://www.google.com&lt;/A&gt;, &lt;A href="https://www.cisco.com" target="_blank"&gt;https://www.cisco.com&lt;/A&gt;&lt;/EM&gt; or other https website. But, i am facing the problem with other https site like (gmail, facebook). I can't go to those website. how can do that ? Please help me. I have attached some screenshot. Thanks.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/capture_90.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/capture3_3.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:05:18 GMT</pubDate>
    <dc:creator>linlinoo</dc:creator>
    <dc:date>2019-03-12T13:05:18Z</dc:date>
    <item>
      <title>ASA with Firepower SSL inspection problem for some https website</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978793#M1019745</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now, i am testing ASA firepower SSL inspection with 6.0. I configured CA as FSMC, SSL policy, Access control rules. Then i can go to &lt;EM&gt;&lt;A href="https://www.google.com" target="_blank"&gt;https://www.google.com&lt;/A&gt;, &lt;A href="https://www.cisco.com" target="_blank"&gt;https://www.cisco.com&lt;/A&gt;&lt;/EM&gt; or other https website. But, i am facing the problem with other https site like (gmail, facebook). I can't go to those website. how can do that ? Please help me. I have attached some screenshot. Thanks.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/capture_90.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/capture3_3.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978793#M1019745</guid>
      <dc:creator>linlinoo</dc:creator>
      <dc:date>2019-03-12T13:05:18Z</dc:date>
    </item>
    <item>
      <title>Most likely your computer</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978794#M1019746</link>
      <description>&lt;P&gt;Most likely your computer doesn't trust FSMC CA. &amp;nbsp;Firefox maintains it's own Trusted CA list where as most of the other browsers get their trusted CA list from the OS. Make sure you import the FSMC CA into your trusted certificate store via the Microsoft Certificate snap-in and trusted CA store in Firefox.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also Chrome will prevent man in the middle certificates to google websites. &amp;nbsp;If you use chrome you will need to make an exception to not decrypt google websites: google.com, gmail.com, youtube.com.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-Smalley&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2016 16:43:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978794#M1019746</guid>
      <dc:creator>Greg Smalley</dc:creator>
      <dc:date>2016-07-27T16:43:15Z</dc:date>
    </item>
    <item>
      <title>Hi Greg,</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978795#M1019747</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks. I already tried like that. It is OK. But, we can't able to import certificate on every PC or laptop in the live network. Right ? We can have 100 or 1000 users in our network. So, how can i do that to automatically import from Firewall to clients. We would like to also block FB chat, post, comment or others. How can we do that ? I already tried to block chat, post. It is not working on version 6.0.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2016 06:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978795#M1019747</guid>
      <dc:creator>linlinoo</dc:creator>
      <dc:date>2016-07-28T06:33:48Z</dc:date>
    </item>
    <item>
      <title>On a network you would</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978796#M1019748</link>
      <description>&lt;P&gt;On a network you would typically use Group Policy to disperse the needed certificate into the Trusted certificate store. &amp;nbsp;If you are using FireFox you would need to use something like PoilicyPak as FireFox doesn't natively use the Microsoft Cert store.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2016 13:09:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978796#M1019748</guid>
      <dc:creator>Greg Smalley</dc:creator>
      <dc:date>2016-07-28T13:09:50Z</dc:date>
    </item>
    <item>
      <title>Thanks again. How about your</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978797#M1019749</link>
      <description>&lt;P&gt;Thanks again. How about your idea to block FB chat, post or other social messaging app with cisco firepower? Actually, it can not block ?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 01:24:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-ssl-inspection-problem-for-some-https-website/m-p/2978797#M1019749</guid>
      <dc:creator>linlinoo</dc:creator>
      <dc:date>2016-07-29T01:24:23Z</dc:date>
    </item>
  </channel>
</rss>

