Unable to decrytion SSL web access by NGAF

Nguyen Quoc Bin Lv1Posted 16 Aug 2023 11:27

i try configuration decrytion SSL web site (NGAF Firewall 5100 license availabled, version software firewall is 8.0.47) , but not working. See more information as attachment screenshot.
Please help me, i don't know where is wrong

1. Config Decryption.png (41.27 KB, Downloads: 428)

1. Config Decryption.png

2. error decrytion.png (128.23 KB, Downloads: 422)

2. error decrytion.png

Newbie517762 has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

HiHi,

Attached is the file with the decryption steps for configuring the internal server.
Use it as a reference.
Decryption data to internal Server.pdf (412.45 KB, Downloads: 472)
Is this answer helpful?
faysalji Lv3Posted 21 Aug 2023 22:10
  
Here are a few things to check:
  • Make sure that the certificate for the *.genK.vn website is installed on the NGAF firewall. You can do this by going to Security > SSL Decryption > Certificates and uploading the certificate file.
  • Make sure that the *.genK.vn website is included in the list of websites that are allowed to be decrypted. You can do this by going to Security > SSL Decryption > Rules and adding a rule for the *.genK.vn website.
  • Make sure that the NGAF firewall is properly configured to decrypt SSL traffic. You can check the configuration by going to Security > SSL Decryption > Settings.

If you have checked all of these things and the SSL decryption is still not working, you can contact Sangfor support for help.
Here are the steps on how to configure SSL decryption for the *.genK.vn website on the NGAF firewall:
  • Log in to the NGAF management console.
  • Click on "Security".
  • Click on "SSL Decryption".
  • Click on "Certificates".
  • Click on "Upload" and select the certificate file for the *.genK.vn website.
  • Click on "Save".
  • Click on "Rules".
  • Click on "Add".
  • In the "Name" field, enter a name for the rule.
  • In the "Domain" field, enter the domain name of the website, which in this case is *.genK.vn.
  • In the "Action" drop-down menu, select "Decrypt".
  • Click on "Save".
  • Click on "Settings".
  • Make sure that the "Enable SSL Decryption" checkbox is checked.
  • Click on "Save".

Once you have completed these steps, the NGAF firewall should start to decrypt SSL traffic for the *.genK.vn website.
I hope this helps!
Naomi Posted 21 Aug 2023 16:48
  
If your are not sure what is next, you can contact support team of sangfor and they will help you.
RegiBoy Lv5Posted 21 Aug 2023 16:48
  
Ensure that your NGAF Firewall 5100 has a valid license for SSL decryption and that you are using a firmware version that supports SSL decryption features. Check with Sangfor support or documentation for compatibility.
isabelita Lv3Posted 21 Aug 2023 16:47
  
Some websites may have issues when being decrypted. Verify if you have configured any URL exclusions in the SSL decryption profile for websites that should not be decrypted.
MISMIS Lv3Posted 21 Aug 2023 16:47
  
SSL decryption can sometimes cause issues with certain clients or applications that expect a direct SSL connection. Check if the websites you are trying to decrypt are compatible with SSL interception.
Noah19 Lv3Posted 21 Aug 2023 16:46
  
Some websites use certificate pinning or other security mechanisms to prevent interception. These sites might not work with SSL decryption. Sangfor may have a bypass mechanism for such cases, so check the documentation.
NeTSec Lv3Posted 21 Aug 2023 16:46
  
If you've followed these steps and are still facing issues, it's recommended to reach out to Sangfor support. They can provide specific guidance based on your configuration and assist with troubleshooting.
noime Lv3Posted 21 Aug 2023 16:45
  
If you've followed these steps and are still facing issues, it's recommended to reach out to Sangfor support. They can provide specific guidance based on your configuration and assist with troubleshooting.
Farina Ahmed Lv5Posted 21 Aug 2023 13:56
  
One possible solution to this issue is to make sure that you have properly configured the SSL CA certificate and that you are using the same certificate in your NGAF security rule.

Checklist for troubleshooting SSL decryption issues on your NGAF Firewall 5100 with software version 8.0.47:

Check Logs: Examine firewall logs for SSL decryption error messages.

Certificates: Ensure valid SSL decryption certificates are installed.

Certificate Trust: Import and trust certificates on client devices.

SSL Policy: Verify SSL inspection policy settings and rules.

Cipher Suites: Confirm compatibility between firewall and server cipher suites.

Interception Bypass: Some sites prevent SSL interception (HPKP, HSTS).

Performance: Ensure firewall hardware handles decryption load.

Firmware Updates: Apply available updates or patches.

DNS Resolution: Check DNS settings for accurate domain resolution.

Troubleshooting Tools: Use built-in firewall tools for insights.

Support: Engage vendor support for specific guidance.
Imran Tahir Lv4Posted 21 Aug 2023 13:40
  
configure ssl certificates and call these certificates in you NGAF security roles

I Can Help:

Change

Moderator on This Board

11
7
5

Started Topics

Followers

Follow

1
3
5

Started Topics

Followers

Follow

0
4
5

Started Topics

Followers

Follow

67
20
3

Started Topics

Followers

Follow

3
14
3

Started Topics

Followers

Follow

1
137
3

Started Topics

Followers

Follow

Board Leaders