Wednesday, July 17, 2019

URL filtering block pages on SSL without installed CA cert

We are trying to get a customer's guest wifi set up with URL filtering that displays a block page.

It's easy to do the filtering, and with SSL interception we can serve the block page, but you're still left with a certificate error and this is generating user complaints.

As this is guest wifi, installing the firewall's forward-trust cert as a CA is not an option. But the customer insists they had it working before with Fortigate.

Is this possible via DNS-based filtering somehow, or else when using an explicit web proxy?



No comments:

Post a Comment