cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2545
Views
5
Helpful
4
Replies

FirePOWER 'response page' for SSL/TLS sites being blocked?

Thomas Winther
Level 1
Level 1

Hi there,

When FirePOWER is blocking SSL/TLS sites it would be preferable to see a response page, like with the HTTP pages.

Is that possible? I guess it is with the enabling of SSL inspection?

Any good guidance?

 

Kind regards

Thomas Winther

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

It's not possible at this time - even with the enabling of SSL inspection.

I just had a customer ask the same question. They have an AMP appliance inline with SSL decryption policy active and working with their trusted internal certificate.

We confirmed with the TAC that the response page cannot be inserted in the case of an SSL-decrypted inspection.

View solution in original post

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

It's not possible at this time - even with the enabling of SSL inspection.

I just had a customer ask the same question. They have an AMP appliance inline with SSL decryption policy active and working with their trusted internal certificate.

We confirmed with the TAC that the response page cannot be inserted in the case of an SSL-decrypted inspection.

any idea when we can present block response page to HTTPS block sites? Thank you
CCIE 18676

It's not even in the just-released version 6.0.

I haven't heard anything about it being on the future roadmap (or not).

Are there any news in this case?
We use Firepower Services in the latest Version an enabled URL Filtering with Access Control Policy.
But most sites uses https instead of http an so the user get's a timeout Page instead of the Blocking response page, which is misleading for a normal user.
Review Cisco Networking for a $25 gift card