Skip to main content
EMES
New Member
May 2, 2017
Question

SSL Deep Packet Inspection Troubleshooting Methodology

  • May 2, 2017
  • 3 replies
  • 19945 views

Hi Everyone,

 

Lets say I have an application that I need to bypass from deep inspection, Onenote for example. In 5.2 we had the command "diag debug application ssl" that would should be the cn/sni of the certificates as the session was happening. Within 5.4 and 5.6 that command is missing. How would I go about doing the same thing? If I need to bypass it seems like web filtering is the only option when its monitoring to pull the fqdn that we may need to bypass.

 

Thank you for your time

    3 replies

    hmtay_FTNT
    Staff
    Staff
    May 2, 2017

    Hi Eugene,

     

    The new commands are "diagnose wad enable category ssl". You can modify the level at "diagnose wad enable level <>" to determine how detailed you want your command printed out. Then "diagnose debug enable".

     

    I did a sample with "apis.google.com". 

     

    wad_ssl_sock_port_exec_up_forward(10691): sp=0x317182b8/6 wad_ssl_proxy_srv_on_client_hello(5835): sp=0x317182b8/6 cert_inspect=0 minor ver/min/max=3/0/3. wad_ssl_proxy_srv_on_client_hello(5865): sp(0x317182b8) get clt_hello svr_name(api.google.com), copy to hostname(0x32761330) wad_ssl_proxy_srv_on_client_hello(5924): Sending https exempt request for hostname=api.google.com wad_ssl_port_exempt_https_request(4446): sec_profile=0x318d442c url_filter=0 deep_scan=1 cert_inspect=0 wad_ssl_port_exempt_https_request(4452): ssl-exempt result: exempt_type=exempt_type_addr hostname(0x32761330)=api.google.com wad_tp_webproxy_ssl_exempt_log(213): sent LOG_DATA_SSLACTION

     

    Hope this answers your question.

     

    HoMing

    EMES
    EMESAuthor
    New Member
    May 3, 2017

    hmtay wrote:

    Hi Eugene,

     

    The new commands are "diagnose wad enable category ssl". You can modify the level at "diagnose wad enable level <>" to determine how detailed you want your command printed out. Then "diagnose debug enable".

     

    I did a sample with "apis.google.com". 

     

    wad_ssl_sock_port_exec_up_forward(10691): sp=0x317182b8/6 wad_ssl_proxy_srv_on_client_hello(5835): sp=0x317182b8/6 cert_inspect=0 minor ver/min/max=3/0/3. wad_ssl_proxy_srv_on_client_hello(5865): sp(0x317182b8) get clt_hello svr_name(api.google.com), copy to hostname(0x32761330) wad_ssl_proxy_srv_on_client_hello(5924): Sending https exempt request for hostname=api.google.com wad_ssl_port_exempt_https_request(4446): sec_profile=0x318d442c url_filter=0 deep_scan=1 cert_inspect=0 wad_ssl_port_exempt_https_request(4452): ssl-exempt result: exempt_type=exempt_type_addr hostname(0x32761330)=api.google.com wad_tp_webproxy_ssl_exempt_log(213): sent LOG_DATA_SSLACTION

     

    Hope this answers your question.

     

    HoMing

    I've been messing with 5.4 and 5.6, 5.4 doesnt seem to have all the commands you mentioned. 5.6 does have something close, Is the syntax different in 5.4?

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!