Forum Discussion
F5 APM/SWG Forward Proxy problem with HSTS sites
Hi gurus,
I had the lab to test F5 APM/SWG Forward Proxy. All things work well except sites with HSTS as , gmail.com...
Normally, when user puts the URL to browser, it will redirect to the Captive portal of APM. But with these sites, an error display and user cannot continue. I think the problem is HSTS of these sites.
How to resolve it?
Thanks
Phong
3 Replies
Are you sure it is HSTS? Since you mention and gmail, it could also be QUIC. This is a experimental protocol used by Google websites and the Chrome browser. It's an alternative for TLS. It uses port 443/UDP. The BIG-IP will not intercept this traffic. You could try blocking 443/UDP. This will cause the browser to fallback to 443/TCP and make it possible for the BIG-IP to do SSL interception.
See: https://en.wikipedia.org/wiki/QUIC
- Stanislas_Piro2
Cumulonimbus
Hi,
did you configure serverssl profile in your virtual server?
- Anesh
Cirrostratus
sites which send the HSTS header do not like self signed certificates, although in other sites you may be able to ignore the trust error when using ssl forward proxy, for sites using HSTS you need to import the certificate into the browser root trust store..
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
