04-19-2025 12:45 AM
I’m currently testing Cisco Firepower Threat Defense (FTD) version 6.3 deployed in EVE-NG, and it’s managed by Firepower Management Center (FMC) version 6.7.
I’ve configured an SSL decryption policy to perform SSL inspection on all outbound HTTPS traffic. The policy is working as expected for most domains (e.g., Google, YouTube, etc.), but I’ve noticed that SSL inspection is not applied to wikipedia.org and its subdomains, even though:
I’ve double-checked the access control policy, SSL rules, and certificates, and everything seems fine. I’m wondering if this could be related to:
Has anyone experienced similar behavior with Wikipedia or other major domains not being inspected? Any ideas or suggestions for troubleshooting this would be greatly appreciated.
04-20-2025 04:47 AM
I dont known but are FTD in eve-ng have a ssl license.
This need to make ftd encrypt ssl traffic.
MHM
04-21-2025 05:57 AM - edited 04-21-2025 05:58 AM
Yes some other domains like google and youtube are already inspected i can find logs of ssl decryption in connection events for these domain in addition to they have local CA that i configure in FTD
04-21-2025 08:27 AM
Did you verify the Wikipedia https traffic is tcp/443 (SSL/TLS) and not udp/443 (QUIC)?
04-21-2025 08:54 AM
I already make a acp rule that block udp 443 above main rule
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide