
User Interface
R&S
®
GP-U/GP-E/GP-S/GP-T
102
User Manual 3646.3836.02 ─ 01
On the "HTTPS" tab, you can configure the HTTPS proxy independently from the
HTTP proxy. If the HTTPS proxy is active in a connection, the HTTPS traffic is forwar-
ded through the HTTPS proxy on the gateprotect Firewall. This means that users can-
not change any proxy settings in the browser.
The HTTPS proxy serves as a man-in-the-middle. For this purpose, it establishes a
connection to the browser and to the web server. This way, the proxy can analyze the
traffic and apply the URL/content filter and scan for viruses.
When the HTTPS proxy is active, make sure that the DNS server of the gateprotect
Firewall is able to correctly resolve the domains to be accessed. Furthermore, import
the HTTPS Proxy CA of your gateprotect Firewall as a trusted CA into the browser of
all clients.
Field
Description
"ON"/"OFF"
A slider switch indicates whether the HTTPS proxy is active ("ON") or inactive
("OFF"). By clicking the slider switch, you can toggle the state of this service.
The HTTPS proxy is deactivated by default.
"HTTPS Blacklist"
/"HTTPS Whitelist"
You can specify a HTTPS blacklist and/or a whitelist by adding as many
domains as you like into the respective list. Both lists can be applied at the
same time.
Domains in the blacklist are blocked by the gateprotect Firewall and cannot be
accessed by users.
Domains in the whitelist are accepted by the HTTPS proxy without analysis and
become directly available to the users' browser. No certificates are created.
This is necessary for services which employ strict Certificate Pinning like Win-
dows Update (URL:
windowsupdate.com
).
Manually enter a domain in the input field under the appropriate list and click
"Add".
You can edit or delete each single entry in the lists by clicking the appropriate
button next to an entry. For further information, see
Tip:
The domains in either list can contain wildcards: * for whole words, ? for
single characters.
The buttons at the bottom right of the editor panel allow you to shut ("Close") the editor
panel as long as no changes have been made and to store ("Save") or to discard
("Reset") your changes.
Click " Activate" in the toolbar at the top of the desktop to apply your configuration
changes.
VoIP Proxy Settings
With the VoIP proxy, you can use the gateprotect Firewall as proxy for VoIP connec-
tions.
Under "UTM > Proxy > VoIP Proxy Settings", you can configure the VoIP proxy for
your gateprotect Firewall:
Menu Reference