Hi ,
Are you redirecting HTTPS 443 traffic in your extended ACL on the ASA ? Have you enabled HTTPS proxy on the WSA ? If the answer is yes to both I would recommend a simultaneous packet capture on a test client and the WSA. To take a packet capture log into the WSA -> Support and Help -> Packet capture -> 200mg -> Run indefinitely -> Pick the appropriate interfaces that handle client traffic -> No filter -> Submit and commit -> start capture and test.
Sincerely,
Erik Kaiser
WSA CSE
WSA Cisco Forums Moderator
Sincerely,
Erik Kaiser
WSA CSE
WSA Cisco Forums Moderator