<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Have you trusted the self in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525-cx-module/m-p/2810382#M165735</link>
    <description>&lt;P&gt;Have you trusted the self-signed certificate in your client?&lt;/P&gt;
&lt;P&gt;You need to either do that or install a trusted enterprise certificate (if you have a local CA that can issue a certificate). In the case of the latter, you would import the server certificate and key for CX by leaving the "Certificate Initialization Method" set to "Import" when you configure the Device Decryption policy.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Nov 2015 22:17:08 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2015-11-23T22:17:08Z</dc:date>
    <item>
      <title>ASA 5525 CX module</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-cx-module/m-p/2810381#M165734</link>
      <description>&lt;P&gt;We have setup a cisco ASA CX module 9.4 (2) and when we go to block HTTPS traffic for like facebook it blocks it.&lt;/P&gt;
&lt;P&gt;i have carried out following steps&lt;/P&gt;
&lt;P&gt;1)Directting HTTPS traffic to CX&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2)Generating self-sign certificate to intercept https traffic at CX.&lt;/P&gt;
&lt;P&gt;3)Then configure decrypt policy to all https traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My problem is that when i do normal http blocking i see the ASA pop-up of block with the category of the URL, whereas for HTTPS i do not see any pop-up it says certificate issue.&lt;/P&gt;
&lt;P&gt;i have few questions regarding it&lt;/P&gt;
&lt;P&gt;1) Does ASA CX show pop-up for https traffic like it does for http traffic being blocked by it.&lt;/P&gt;
&lt;P&gt;2) Can i use root certificate instead of self-sign certificate if yes , how to find the root certificate to import in CX module.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-cx-module/m-p/2810381#M165734</guid>
      <dc:creator>Aaquib_A1</dc:creator>
      <dc:date>2019-03-12T06:56:00Z</dc:date>
    </item>
    <item>
      <title>Have you trusted the self</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-cx-module/m-p/2810382#M165735</link>
      <description>&lt;P&gt;Have you trusted the self-signed certificate in your client?&lt;/P&gt;
&lt;P&gt;You need to either do that or install a trusted enterprise certificate (if you have a local CA that can issue a certificate). In the case of the latter, you would import the server certificate and key for CX by leaving the "Certificate Initialization Method" set to "Import" when you configure the Device Decryption policy.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2015 22:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-cx-module/m-p/2810382#M165735</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-11-23T22:17:08Z</dc:date>
    </item>
    <item>
      <title>Yes , i have trusted the self</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-cx-module/m-p/2810383#M165736</link>
      <description>&lt;P&gt;Yes , i have trusted the self signed certificate on the client but still i do not see the&amp;nbsp;&lt;SPAN&gt;CX banner notification for https traffic it gives secure connection failed message.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 06:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-cx-module/m-p/2810383#M165736</guid>
      <dc:creator>Aaquib_A1</dc:creator>
      <dc:date>2015-11-24T06:09:18Z</dc:date>
    </item>
    <item>
      <title>I dont beleieve it sends a</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-cx-module/m-p/2810384#M165737</link>
      <description>&lt;P&gt;I dont beleieve it sends a banner for a drop of encypted traffic. it just drops the TCP session, resulting in the browser error you see.&lt;/P&gt;
&lt;P&gt;Reference this note:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asacx/9-3/user/guide/b_User_Guide_for_ASA_CX_and_PRSM_9_3/prsm-ug-cx-decryption.html#concept_CD90D495EA6C477E88073250FBACA83A&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 17:39:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-cx-module/m-p/2810384#M165737</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-11-25T17:39:33Z</dc:date>
    </item>
  </channel>
</rss>

