02-12-2025 02:00 AM
Hey,
I'm trying to setup Access Policy on SSE that allows access to Whatsapp Web but blocks uploading and downloading files from Whatsapp Web.
I have created an Access Policy rule that allows from any source to the Whatsapp destination, Advanced Application Control is also enabled in this rule and blocks upload to Whatsapp, also, a Security Profile in configured in this rule that has File Type Blocking enabled.
I'm testing this configuration with a computer that is configured with a PAC file and the rules doesn't seem affect the traffic, I can still upload and download from Whatsapp Web (I have QUIC disabled in the Microsoft Edge browser).
What am I doing wrong?
02-21-2025 06:19 AM - edited 02-21-2025 06:19 AM
From a quick glance it looks like you have decryption disabled in your security profile. This needs to be enabled.
https://docs.sse.cisco.com/sse-user-guide/docs/advanced-application-controls
If advanced application control is not working as expected, check the following:
02-24-2025 02:20 AM
Thank you for your response,
I have enabled Decryption in my Security Profile and now uploads are being blocked as expected, but, I also have enabled File Type Blocking and it does not block files that I download from Whatsapp Web conversations.
02-25-2025 07:41 AM
From the info in the docs, it looks like this granularity about Download is not provided, only Upload
02-25-2025 07:46 AM
From what I understand, this chart refers to Advanced Application Control and not File Type Blocking.
I am trying to configure File Type Blocking which is different.
02-27-2025 11:28 AM
Are your sure the file type you are downloading matches the file type you are blocking in Secure Access? If so you might want to open a TAC case to further look into the issue.
03-09-2025 03:26 AM
Yes, unfortunately, I am sure.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide