Use the commands in this section to enable or disable the Network Security appliance to whitelist uncategorized third-party URLs for SSL interception.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Verify that the SSL interception whitelist for third-party URL categorization is enabled.
hostname # show url-category stats URL lookup : Enabled Whitelist null url : Disabled Whitelist uncategorized url : Disabled SSL Categorization trend : Enabled Trellix Default Whitelist : Enabled Engine Name : SSL Intercept Module Total urls processed : 4826 Total whitelisted urls : 184 Total NULL url : 715 Total Uncategorized url : 16Enable the appliance to whitelist uncategorized third-party URLs.
hostname (config) # url-category whitelist uncategorized-url enable
Verify your changes.
In the following example, the "
Whitelist uncategorized url:" line of the command output displays "Enabled" to show that the appliance will exclude the uncategorized third-party URLs from decryption.hostname # show url-category stats URL lookup : Enabled Whitelist null url : Disabled Whitelist uncategorized url : Enabled SSL Categorization trend : EnabledTrellix Default Whitelist : Enabled Engine Name : SSL Intercept Module Total urls processed : 4826 Total whitelisted urls : 184 Total NULL url : 715 Total Uncategorized url : 16View the session logger output after enabling this feature.
hostname (config) # session-logger enable hostname (config) # session-logger ssl enable hostname # show session-log ssl continuous
Feb 25 23:15:16 192.169.210.138 56089 176.74.176.178 443 cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-1,block-0) s_site_name:internettraffic.click error:NFor detailed information about the SSL session logger and the log details on SSL flows for SSL interception traffic, see Viewing the connection event logs.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Verify that the SSL interception whitelist for third-party URL categorization is enabled.
hostname # show url-category stats URL lookup : Enabled Whitelist null url : Disabled Whitelist uncategorized url : Disabled SSL Categorization trend : EnabledTrellix Default Whitelist : Enabled Engine Name : SSL Intercept Module Total urls processed : 4826 Total whitelisted urls : 184 Total NULL url : 715 Total Uncategorized url : 16Disable the appliance from whitelisting uncategorized third-party URLs.
hostname (config) # no url-category whitelist uncategorized-url enable
Verify your changes.
In the following example, the "
Whitelist uncategorized url:" line of the command output displays "Disabled" to show that the appliance will not exclude the uncategorized third-party URLs from decryption.hostname # show url-category stats URL lookup : Enabled Whitelist null url : Disabled Whitelist uncategorized url : Disabled SSL Categorization trend : EnabledTrellix Default Whitelist : Enabled Engine Name : SSL Intercept Module Total urls processed : 890483 Total whitelisted urls : 22125 Total NULL url : 4111 Total Uncategorized url : 199634View the session logger output after disabling this feature.
hostname (config) # session-logger enable hostname (config) # session-logger ssl enable hostname # show session-log ssl continuous
Feb 25 23:15:16 192.169.210.138 56089 176.74.176.178 443 cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:internettraffic.click error:N
For detailed information about the SSL session logger and the log details on SSL flows for SSL interception traffic, see Viewing the connection event logs.