Sonicwall and HTTPS sites

httpssonicwall

I've been asked to investigate an issue with our company's network. The Sonicwall appliance was already setup and the one who did has already left the company.

The problem is that the hosts under the designated normal user IPs cannot access HTTPS sites(with Google being the only exception I have seen so far). If it helps, the HTTPS sites the users are trying to access are business-related sites and even some government-owned sites. What is strange is that any host that was assigned an IP address that does not go through Sonicwall had no problem accessing the HTTPS sites (I used the term loosely as it was what the guy who set it up told me). Sadly, I cannot contact the guy anymore so I am forced to investigate this alone.

I have tried applying the addresses of the HTTPS sites at the Allowed Domains in the CFS but it still did not work. I also checked the firewall access rules and found the IP allocation that was set to go from any source to any destination. Naturally, I thought that maybe this was it. Interestingly, it was not even enabled. The checkbox aligned to it was empty. Seeing this, I tried changing a unit's IP address to an address in this allocation. Surprisingly enough, the HTTPS sites loaded.

Here is a screenshot in one of the units:
You can see that Google in HTTPS has loaded but Yahoo mail hasn't

I am stumped. It's not in the CFS, its not in the access rules. I even tried adding access rules that would explicitly allow HTTPS connections to go through but it still did not work. Is there any other way for Sonicwall to filter the traffic other than the firewall and CFS? Because maybe that is where the exclusion for the IP allocation is configured.

Best Answer

I'm reaching here, but I am assuming from your screenshot that these are XP machines. I'm going to further assume that the content filter was being applied transparently (no proxy settings). If that's the case HTTPS sites will not work in IE. To test the theory, turn CFS back on, and try firefox. I further presume someone has excluded google from being filtered, and that's why you can get there.

If I'm right - it's due to the lack of support for SNI in your browser. Upgrade browser (to non IE), OS (vista + IE is ok) or use an explicit proxy.

Related Topic