You can use the url-category whitelist null-sni enable command to enable the SSL interception whitelist when SNI support between the server and the client is not available.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Whitelist URLs with an empty SNI URL category.
hostname (config) # url-category whitelist null-sni enable
View URL entries that were processed and whitelisted after the empty SNI URL category feature was enabled.
hostname (config) # show url-category stats URL lookup : Enabled Whitelist null url : Enabled Whitelist uncategorized url : Enabled SSL Categorization trend : Enabled FireEye Default Whitelist : Enabled Engine Name : SSL Intercept Module Total urls processed : 2158 Total whitelisted urls : 119 Total NULL url : 29 Total Uncategorized url : 13
View the session logger output after enabling this feature.
hostname (config) # session-logger enable hostname (config) # session-logger ssl enable hostname # show session-log ssl continuous
Dec 14 10:24:21 10.10.10.10 41393 10.10.10.11 443 cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-1,block-0) s_site_name:N/A error:N/A
For detailed information about the SSL session logger and the log details on SSL flows for SSL interception traffic, see Viewing the connection event logs.