Stormshield: url filtering https without decryption

Presentation

In this tutorial, we’ll see how to set up https url filtering (SSL) without needing to decrypt and therefore deploy the stormshield certificate.

This solution does not display a blocking page, users will have a blank page.

Implementing https URL filtering

1. Log in to your Stormshield.
Stormshield : filtrage url https

2. In the menu on the left, go to SECURITY POLICY 1 then SSL filtering 2 and click on Add rules by category 3.
Politique SSL

3. All categories 1 on your Stormshield should be added to the filter policy.
Liste des catégories

4. You must now for each category 1, modify the action. To block, you must put the Block without decryting action and pass Pass without decryting.
Choix de l'action par catégorie

5. Check that the last line is the category any 1. Depending on the desired policy, modify the action. Then click Apply 2 to save.
Parametrage du any

6. Go to Filtering – NAT 1, add a new SSL inspection rule 2.
Ajout d'une règle

7. Configure source and destination 1, select the SSL profile you just made 2, and click Finish 3 to add the rules.
Configuration de la regle

8. Two rules are created, you can see at the level of the first application filtering. Click Save and apply 1 to apply the changes.
Visualisation des regles


Related Posts


Sophos XG: installation on Hyper-V

In this tutorial, we will have how to install a Sophos XG firewall on a virtual machine with Hyper-V. For this article, I used the Sophos XG home version which is available for free. Prerequisites Dow

Redirect HTTP to HTTPS over IIS

In this tutorial, we'll see how to automatically redirect http requests to https under IIS. Prerequisites : Valid configuration of your site with SSL. Have the Rewrite module installed under IIS. The

How to install and configure Windows server routing

In this tutorial, I will explain how to set up routing with Windows Server. I regularly use this role in the different labs that I put in place under Hyper-V. I isolate the test platform with a privat

Leave a Comment