01-02-2017 02:55 AM - edited 03-12-2019 01:43 AM
Hello,
Very eager to know about how HTTPS works on CISCO ASA with firepower subscription?
can anyone please tell me how cisco asa scan HTTPS packets and block web categories applied by admin? Does it use certificate or something else?
01-02-2017 03:07 AM
FirePower gets a certificate that has to be trusted by your clients or come from an internal trusted CA.
When the client connects to a HTTPS-ressource (can also be other services that work with TLS), then FP issues a new certificate on the fly with the subject of the destination server. With that it makes itself a Man-in-the-middle and can inspect the data.
In general, it's the same as probably all HTTP-inspecting gateways work.
01-02-2017 04:06 AM
Thanks for clearing my doubts.
Is there any document for details description of HTTPS inspecting about Cisco firepower?
01-02-2017 04:54 AM
The config guide shows it in much detail:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide