cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2394
Views
0
Helpful
1
Replies

FTD SSL Inspection - Block UPLOADS

Fantas
Level 1
Level 1

Hi,

 

I want to block uploads to all public drive like dropbox, onedrive, gdrive etc.

I want to block attachment/uploads to gmail, facebook, youtube and linkedin

 

I have already setup SSL and ACL policies on FMC and been pushed to FTDs,

My SSL policy have cert Resign and any source and destination

ACL policy have application gmail attachment, onedrive upload, linkedin uploads, youtube upload and action Block and reset

 

Even after above changes I can still able to attach files in gmail and dropbox

 

Any idea if I am missing anything.

 

 

 

 

 

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

I know Dropbox does certificate pinning.

https://blog.dropbox.com/topics/company/weve-got-your-back

https://www.dropbox.com/business/trust/security/architecture

I suspect Gmail does to but cannot find a definitive reference saying so.

Certificate pinning prevents intermediate devices such as FTD from acting as a man in the middle and decrypting the traffic - even if the client trusts the certificate.

Review Cisco Networking for a $25 gift card