Forum Discussion
Why is decrypted Gemini traffic sent as HTTP over 443 via Explicit Proxy DLP, not https
Hello DevCentral Community,
I am running F5 SSL Orchestrator (SSLO) integrated with an inline DLP device configured in HTTP Proxy (Explicit Proxy) mode.
SSLO successfully decrypts outbound TLS traffic and forwards it to the DLP proxy in plaintext HTTP/1.1 format. However, I noticed a difference in how the destination port is handled depending on the target site:
- ChatGPT / Claude: The decrypted HTTP/1.1 request is forwarded to the DLP Proxy with the destination port changed to Port 80 (Explicit HTTP).
- Gemini (gemini.google.com): The decrypted HTTP/1.1 request is also forwarded as plaintext to the DLP Proxy, but the destination port remains as Port 443 (HTTP over 443).
Since the DLP is receiving this decrypted traffic via an Explicit HTTP Proxy connection, why does SSLO preserve Port 443 specifically for Gemini while translating the destination port to 80 for ChatGPT and Claude?
Could this be related to how SSLO handles the original HTTP CONNECT tunneling request, ALPN negotiation, or L7 HTTP Profile settings when rewriting proxy headers for Google services?
Any advice on how to unify the behavior so Gemini traffic is also forwarded as Explicit HTTP over Port 80 would be greatly appreciated.
Thank you!
ps. The following error message appears when port remap is enabled:
[OrchestratorConfigProcessor] Deployment failed for Error: [HAAwareICRDeployProcessor] Error: transaction failed:01071912:3: CLIENTSSL_HANDSHAKE event in rule (/Common/ssloS_GENERIC_HTTP.app/ssloS_GENERIC_HTTP-port_remap) requires an associated CLIENTSSL profile on the virtual-server (/Common/ssloS_GENERIC_HTTP.app/ssloS_GENERIC_HTTP-t-4).
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com