Hi. My company is intending to purchase the Wingate Enterprise and right now we are evaluating it. One of the criteria of evaluation is that we need to successfully block all social media e.g. Facebook, Twitter that is operating on HTTPS. I am evaluating on Wingate 8. And I hope you can help me out a bit here.
I have dug around and it says that in order to effectively block HTTPS sites, we need to enable SSL inspection.
Prior to that I have defined a block URLs under Control Panel > Data > Global Data > Banned Sites.
Then, I create an certificate in Control Panel > Certificates > Add Certificate. The following Encryption Options were specified:-
Encryption: DES in CBC mode
Options: Use 65537 for the exponent
Size: 1024bits
The certificate generated was then exported out using Windows Certificate Export Wizard and installed on a workstation.
Then, I enable the SSL Inspection option in Control Panel > Services > WWW Proxy Server > SSL Inspection. Enable inspection of encrypted content option is ticked, Signer certificate pointed to the certificate generated in Step 2. Validate server certificate, Perform validation on entire certificate chain and Block access if certificate validation fails option were all checked.
On my testing workstation, I am still able to browse Facebook. Is there any portion here which I am doing wrongly? Any help is greatly appreciated.