cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2068
Views
10
Helpful
4
Replies

Umbrella block page and SSL decryption

Chess Norris
Level 4
Level 4

Hello,

We are currently running Firepower FTD with URL filtering, but since we dont use a SSL policy, the users will not get a block page for SSL/HTTPS URL:s. I belive this will not be an issue with Umbrella since it's a cloud solution, but I just need to confirm this before suggestion this solution.

Thanks

/Chess

1 Accepted Solution

Accepted Solutions

@Chess Norris you can block HTTPS URLs in Umbrella, to use the block page you will need to install the Umbrella root certificate (without it you'd get a certificate error).

View solution in original post

4 Replies 4

@Chess Norris you can block HTTPS URLs in Umbrella, to use the block page you will need to install the Umbrella root certificate (without it you'd get a certificate error).

Installing the Umbrella root certificate (usually via GPO or similar in an AD environment) works fine for managed computers. If you're blocking guests or unmanaged devices they will still get the untrusted certificate warning page.

Thanks Marvin. Yes, thats a good point about guest networks. In this case all computer are manged, so it shouldn't be an issue.

The option is to do SSL decryption in our FTD, but we probably need to invest more money in hardware if we go that route.

/Chess

Chess Norris
Level 4
Level 4

Just the answer I was looking for.

Thanks

/Chess