Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Working With Encrypted Data > Enabling SSL support
Enabling SSL support
Help | Content Gateway | v8.5.x
1.
In the Content Gateway manager, go to the Configure > My Proxy > Basic > General tab.
2.
 
Note 
3.
Click Apply and then Restart.
4.
5.
Go to the Configure > Protocols > HTTPS page.
6.
Specify the HTTPS Proxy Server Port used for client to Content Gateway connections (8080, by default).
If traffic is transparent on 443, a default ARM redirection rule redirects the requests to 8080. See Configure > Networking > ARM > Redirection Rules.
7.
 
Note 
Set the value to 0 to turn off tunneling of non-SSL traffic.
 
Warning 
When tunneling is enabled, Forcepoint Web Security behavior varies based on the type of proxy deployment.
*
When Content Gateway is an explicit proxy, a URL lookup is performed and policy is applied before the SSL connection request is made. Transactions are logged as usual.
*
When Content Gateway is a transparent proxy, if there is an SNI in the request, Content Gateway gets the hostname from the SNI and performs URL filtering based on the hostname. Otherwise, when Content Gateway sends the connect to the server, the unknown protocol error causes the request to be tunneled without the proxy being aware of it, and no transaction is logged.
Tunneling of WebSocket traffic over HTTPS (secure mode) is enabled by default.
 
Note 

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Working With Encrypted Data > Enabling SSL support
Copyright 2023 Forcepoint. All rights reserved.