121
As such, if you want to block a specific web category or web site that is using HTTPS, enter
the web site as blocked in the Content Filtering tab, select a TFRS that has SSL Filtering and
choose one of the HTTPS/SSL Filtering options.
HTTPS/SSL Blocking
There is an additional TFRS for SSL traffic entitled SSL Block. This TFRS does not perform
any content filtering, web logging, spyware scanning, and virus scanning on HTTPS web
sites. This TFRS only prohibits all HTTPS/SSL traffic from passing through Optinet. By
default there is only one TFRS that is set to block HTTPS traffic. This TFRS is called Web
Anonymous Proxy Guard + SSL Block.
This TFRS performs content filtering, web logging, spyware scanning, and virus scanning for
HTTP traffic (Web Filter). This TFRS also prohibits HTTP traffic on any port other than port
80 or a designated proxy port (Anonymous Proxy Guard). Finally this TFRS prohibits all
HTTPS/SSL traffic from passing through Optinet (SSL Block).
HTTPS/SSL Filtering Requirements
HTTPS/SSL Filtering does place additional processing load on Optinet. As such, HTTPS
traffic cannot be more 25% of non SSL model bandwidth specs (see following table). Before
enabling any form of HTTPS/SSL Filtering, please confirm that your HTTPS traffic does not
exceed the specified amount listed below.
Model Max
Total
Throughput Max HTTPS Throughput
Optinet 5
5 Mbps
1.25 Mbps
Optinet 20
20 Mbps
5 Mbps
Optinet 20 SSL
20 Mbps
20 Mbps
Optinet 45 SSL
45 Mbps
45 Mbps
Optinet 100 SSL
100 Mbps
100 Mbps
Optinet 200 SSL
200 Mbps
200 Mbps
SSL Acceleration Optinet models come equipped with SSL Accelerators which perform part
of the HTTPS/SSL Filtering, relieving the load on Optinet. These models are indicated with
the SSL description above.
Also, HTTPS/SSL Filtering does require a live Internet connection preferably active for at
least 24 hours. A good practice is to install Optinet and let the device collect data for at
least 24 hours. This way you can verify via Report -> Application Overview -> HTTPS if the
amount of traffic is below 25% of The Optinet maximum bandwidth specification and
afterwards enable HTTPS/SSL Filtering.
Lastly, Optinet only supports HTTPS/SSL Filtering for web browsers that use SSL v2.0, SSL
v3.0, and Transport Layer Security (TLS) v1.0. Current web browsers use these versions by
default, but you may want to verify that your network’s web browsers are updated.
In addition to bandwidth and connections requirements, HTTPS/SSL Filtering requires that
you enable two options under the Advanced Setup tab (Admin -> Configuration ->