cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
710
Views
0
Helpful
2
Replies

Proxy not seeing https

ashaw216
Level 1
Level 1

We have an ASA configured for WCCP, forwarding to a WSA in Transparent mode. HTTP traffic is blocked correctly per our policies. However, even though HTTPS Proxy is enabled with a root cert and Decryption Policy is set for global to Decrypt, the HTTPS traffic is not blocked and doesn't even show up in the reports. If we set the web browser manually to use the Ironport for proxy, it works. I thought the whole point of WCCP and transparent mode was to not have to define the proxy at the browser level?

2 Replies 2

Did you add the https ports on the Network/Transparent Redirection page? 

Does the ACL that you have on the ASA have any ports on it? the service should be "ip"

"Standard Service" was changed to Dynamic (90) and ports configured to 80,443. Firewall is set to ip as you mention (i.e. no specific ports.)