Edge SWG (ProxySG) not enforcing client and server TLS versions set in policy
search cancel

Edge SWG (ProxySG) not enforcing client and server TLS versions set in policy

book

Article ID: 383869

calendar_today

Updated On:

Products

ProxySG Software - SGOS ISG Proxy Advanced Secure Gateway Software - ASG SSL Visibility Appliance Software

Issue/Introduction

You have policy on your Edge SWG (ProxySG) which has TLS version control policy. However, the policy doesn't appear to do anything even though it is matching the policy rule.

 

Environment

  • Edge SWG (ProxySG) running SGOS 7.3 or later
  • SSL Visibility (SSLV) offloading configured
  • Policy rules setting TLS versions for sites similar to:
    •  
    • <ssl>
      condition=TLSv12_Limit client.connection.max_ssl_version(tlsv1.2) server.connection.max_ssl_version(tlsv1.2)

Cause

SSLV offloading overrides Edge SWG (ProxySG) TLS policy controls

Resolution

The policy on the Edge SWG (ProxySG) doesn't apply to SSLV offloaded traffic. Since the SSL control is on the SSLV for offloading, you can control the TLS versions from the SSLV device.

Refer to the technical document Configure Rulesets to Handle SSL Traffic for setting the TLS version on the SSLV