<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Policy Not Applied to Wikipedia Domain in Cisco Firepower 6.3 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5283353#M1120666</link>
    <description>&lt;P&gt;Yes some other domains like google and youtube are already inspected i can find logs of ssl decryption in connection events for these domain in addition to they have local CA that i configure in FTD&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Apr 2025 12:58:32 GMT</pubDate>
    <dc:creator>elkabeermg</dc:creator>
    <dc:date>2025-04-21T12:58:32Z</dc:date>
    <item>
      <title>SSL Policy Not Applied to Wikipedia Domain in Cisco Firepower 6.3 (EVE</title>
      <link>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5282929#M1120646</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I’m currently testing Cisco Firepower Threat Defense (FTD) version 6.3 deployed in EVE-NG, and it’s managed by Firepower Management Center (FMC) version 6.7.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I’ve configured an SSL decryption policy to perform SSL inspection on all outbound HTTPS traffic. The policy is working as expected for most domains (e.g., Google, YouTube, etc.), but I’ve noticed that SSL inspection is not applied to wikipedia.org and its subdomains, even though:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;There are no exclusions or bypass rules configured in the SSL policy.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The domain is not listed in any trusted CA override or rule.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;No rule explicitly matches or excludes Wikipedia.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The client browser shows a direct connection using the real Wikipedia certificate, not the re-signed one from the FTD device.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;I’ve double-checked the access control policy, SSL rules, and certificates, and everything seems fine. I’m wondering if this could be related to:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;A default system-level bypass in FTD for specific websites?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Some behavioral limitation when running FTD in EVE-NG?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;Has anyone experienced similar behavior with Wikipedia or other major domains not being inspected? Any ideas or suggestions for troubleshooting this would be greatly appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Apr 2025 07:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5282929#M1120646</guid>
      <dc:creator>elkabeermg</dc:creator>
      <dc:date>2025-04-19T07:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Policy Not Applied to Wikipedia Domain in Cisco Firepower 6.3</title>
      <link>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5283088#M1120653</link>
      <description>&lt;P&gt;I dont known but are FTD in eve-ng have a ssl license.&lt;/P&gt;
&lt;P&gt;This need to make ftd encrypt ssl traffic.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 20 Apr 2025 11:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5283088#M1120653</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-20T11:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Policy Not Applied to Wikipedia Domain in Cisco Firepower 6.3</title>
      <link>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5283353#M1120666</link>
      <description>&lt;P&gt;Yes some other domains like google and youtube are already inspected i can find logs of ssl decryption in connection events for these domain in addition to they have local CA that i configure in FTD&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 12:58:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5283353#M1120666</guid>
      <dc:creator>elkabeermg</dc:creator>
      <dc:date>2025-04-21T12:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Policy Not Applied to Wikipedia Domain in Cisco Firepower 6.3</title>
      <link>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5283416#M1120668</link>
      <description>&lt;P&gt;Did you verify the Wikipedia https traffic is tcp/443 (SSL/TLS) and not udp/443 (QUIC)?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 15:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5283416#M1120668</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-04-21T15:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Policy Not Applied to Wikipedia Domain in Cisco Firepower 6.3</title>
      <link>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5283431#M1120671</link>
      <description>&lt;P&gt;I already make a acp rule that block udp 443 above main rule&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 15:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-policy-not-applied-to-wikipedia-domain-in-cisco-firepower-6/m-p/5283431#M1120671</guid>
      <dc:creator>elkabeermg</dc:creator>
      <dc:date>2025-04-21T15:54:29Z</dc:date>
    </item>
  </channel>
</rss>

