ProSecure Unified Threat Management UTM10 or UTM25 Reference Manual

HTTPS Scan Settings

HTTPS traffic is encrypted traffic that cannot be scanned otherwise the data stream would not be secure. However, the UTM can scan HTTPS traffic that is transmitted through an HTTP proxy, that is, HTTPS traffic is scanned as a proxy between the HTTPS client and the HTTPS server. Figure 6-13shows the HTTPS scanning traffic flow.

Figure 6-13

The HTTPS scanning process functions with the following principles:

The UTM breaks up an SSL connection between an HTTPS server and an HTTP client in two parts:

A connection between the HTTPS client and the UTM.

A connection between the UTM and the HTTPS server.

The UTM simulates the HTTPS server communication to the HTTPS client, including the SSL negotiation, certificate exchange, and certificate authentication. In effect, the UTM functions as the HTTPS server for the HTTPS client.

The UTM simulates the HTTPS client communication to the HTTPS server, including the SSL negotiation, certificate exchange, and certificate authentication. In effect, the UTM functions as the HTTPS client for the HTTPS server.

During SSL authentication, the HTTPS client authenticates three items:

Is the certificate trusted?

Has the certificate expired?

Does the name on the certificate match that of the Web site?

6-34

Content Filtering and Optimizing Scans

v1.0, September 2009

Page 198
Image 198
NETGEAR UTM25-100NAS, UTM10EW-100NAS, UTM25EW-100NAS manual Https Scan Settings