cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
256
Views
2
Helpful
4
Replies

SSL Policy Not Applied to Wikipedia Domain in Cisco Firepower 6.3 (EVE

elkabeermg
Level 1
Level 1

I’m currently testing Cisco Firepower Threat Defense (FTD) version 6.3 deployed in EVE-NG, and it’s managed by Firepower Management Center (FMC) version 6.7.

I’ve configured an SSL decryption policy to perform SSL inspection on all outbound HTTPS traffic. The policy is working as expected for most domains (e.g., Google, YouTube, etc.), but I’ve noticed that SSL inspection is not applied to wikipedia.org and its subdomains, even though:

  • There are no exclusions or bypass rules configured in the SSL policy.
  • The domain is not listed in any trusted CA override or rule.
  • No rule explicitly matches or excludes Wikipedia.
  • The client browser shows a direct connection using the real Wikipedia certificate, not the re-signed one from the FTD device.

I’ve double-checked the access control policy, SSL rules, and certificates, and everything seems fine. I’m wondering if this could be related to:

  1. A default system-level bypass in FTD for specific websites?
  2. Some behavioral limitation when running FTD in EVE-NG?

Has anyone experienced similar behavior with Wikipedia or other major domains not being inspected? Any ideas or suggestions for troubleshooting this would be greatly appreciated.

4 Replies 4

I dont known but are FTD in eve-ng have a ssl license.

This need to make ftd encrypt ssl traffic.

MHM

Yes some other domains like google and youtube are already inspected i can find logs of ssl decryption in connection events for these domain in addition to they have local CA that i configure in FTD 

Did you verify the Wikipedia https traffic is tcp/443 (SSL/TLS) and not udp/443 (QUIC)?

I already make a acp rule that block udp 443 above main rule 

Review Cisco Networking for a $25 gift card