ā04-19-2025 12:45 AM
Iām currently testing Cisco Firepower Threat Defense (FTD) version 6.3 deployed in EVE-NG, and itās managed by Firepower Management Center (FMC) version 6.7.
Iāve configured an SSL decryption policy to perform SSL inspection on all outbound HTTPS traffic. The policy is working as expected for most domains (e.g., Google, YouTube, etc.), but Iāve noticed that SSL inspection is not applied to wikipedia.org and its subdomains, even though:
Iāve double-checked the access control policy, SSL rules, and certificates, and everything seems fine. Iām wondering if this could be related to:
Has anyone experienced similar behavior with Wikipedia or other major domains not being inspected? Any ideas or suggestions for troubleshooting this would be greatly appreciated.
ā04-20-2025 04:47 AM
I dont known but are FTD in eve-ng have a ssl license.
This need to make ftd encrypt ssl traffic.
MHM
ā04-21-2025 05:57 AM - edited ā04-21-2025 05:58 AM
Yes some other domains like google and youtube are already inspected i can find logs of ssl decryption in connection events for these domain in addition to they have local CA that i configure in FTD
ā04-21-2025 08:27 AM
Did you verify the Wikipedia https traffic is tcp/443 (SSL/TLS) and not udp/443 (QUIC)?
ā04-21-2025 08:54 AM
I already make a acp rule that block udp 443 above main rule
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide