<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Block proxy over secure browser in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-block-proxy-over-secure-browser/m-p/1584582#M559196</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, Cisco ASA firewall also does not inspect HTTPS because to inspect encrypted traffic, you would need to be performing man-in-the-middle to you can get the HTTPS connection decrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can take a look at Cisco Ironport WSA or Cisco ScanSafe web filtering solution that does provide HTTPS inspection capabilities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Ironport WSA (appliance):&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps10142/ps10164/data_sheet_c78-586408.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps10142/ps10164/data_sheet_c78-586408.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Scansafe (cloud base):&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps10142/ps11616/DS_web_security.pdf"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps10142/ps11616/DS_web_security.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Mar 2011 21:23:31 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2011-03-25T21:23:31Z</dc:date>
    <item>
      <title>How to Block proxy over secure browser</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-proxy-over-secure-browser/m-p/1584579#M559186</link>
      <description>&lt;P&gt;Having some problems blocking users installing/using secure browsers proxy. Currently runing ASA 5520 ver. 8.3 &amp;amp; IPS SSM-20 7.0 (2) E4 &amp;amp; Websense web filtering. Able to block most proxy sites with Websense that use port 80 but recently found that some users using some products like Njutrino that use their own secure browser that use it's own proxy over SSL connection.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:12:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-proxy-over-secure-browser/m-p/1584579#M559186</guid>
      <dc:creator>smartin</dc:creator>
      <dc:date>2019-03-11T20:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to Block proxy over secure browser</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-proxy-over-secure-browser/m-p/1584580#M559190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since Websense is providing web filtering, you would need to check with Websense why it is not being blocked.&lt;/P&gt;&lt;P&gt;My first guest, as the session is SSL encrypted, Websense will need to inspect the HTTPS packet before able to see the clear text packet. Please check with Websense if HTTPS inspection is configured to decrypt the SSL session.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 06:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-proxy-over-secure-browser/m-p/1584580#M559190</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-03-25T06:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to Block proxy over secure browser</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-proxy-over-secure-browser/m-p/1584581#M559193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Websense cannot inspect a HTTPS proxy connection, please it's impossible to block every proxy server (could be a home proxy), anyway for Cisco ASA to inspect HTTPS ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 12:02:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-proxy-over-secure-browser/m-p/1584581#M559193</guid>
      <dc:creator>smartin</dc:creator>
      <dc:date>2011-03-25T12:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to Block proxy over secure browser</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-proxy-over-secure-browser/m-p/1584582#M559196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, Cisco ASA firewall also does not inspect HTTPS because to inspect encrypted traffic, you would need to be performing man-in-the-middle to you can get the HTTPS connection decrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can take a look at Cisco Ironport WSA or Cisco ScanSafe web filtering solution that does provide HTTPS inspection capabilities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Ironport WSA (appliance):&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps10142/ps10164/data_sheet_c78-586408.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps10142/ps10164/data_sheet_c78-586408.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Scansafe (cloud base):&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps10142/ps11616/DS_web_security.pdf"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps10142/ps11616/DS_web_security.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 21:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-proxy-over-secure-browser/m-p/1584582#M559196</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-03-25T21:23:31Z</dc:date>
    </item>
  </channel>
</rss>

