02-06-2023 01:52 AM
Hello,
We are currently running Firepower FTD with URL filtering, but since we dont use a SSL policy, the users will not get a block page for SSL/HTTPS URL:s. I belive this will not be an issue with Umbrella since it's a cloud solution, but I just need to confirm this before suggestion this solution.
Thanks
/Chess
Solved! Go to Solution.
02-06-2023 02:03 AM
@Chess Norris you can block HTTPS URLs in Umbrella, to use the block page you will need to install the Umbrella root certificate (without it you'd get a certificate error).
02-06-2023 02:03 AM
@Chess Norris you can block HTTPS URLs in Umbrella, to use the block page you will need to install the Umbrella root certificate (without it you'd get a certificate error).
02-06-2023 05:02 AM
Installing the Umbrella root certificate (usually via GPO or similar in an AD environment) works fine for managed computers. If you're blocking guests or unmanaged devices they will still get the untrusted certificate warning page.
02-06-2023 05:16 AM
Thanks Marvin. Yes, thats a good point about guest networks. In this case all computer are manged, so it shouldn't be an issue.
The option is to do SSL decryption in our FTD, but we probably need to invest more money in hardware if we go that route.
/Chess
02-06-2023 02:10 AM
Just the answer I was looking for.
Thanks
/Chess
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide