Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » General Security Discussion » HTTPS filtering

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

HTTPS filtering


Posted by ratbert on August 01, 2007 08:00:20

Please before you say this can not be done. Please read what I'm asking about.

I work for a school district spread out across 8 campuses and 40+ miles between campuses.

We currently have a squid+dansguardian setup transparently doing both URL and content filtering on all http traffic. I'm the only guy here doing this job. So anything that can simplify my time would great. I am trying to find a solution that can restrict access to https sites to only those NOT on my blacklists. I would like a solution that does so without requiring me to touch each machine and each browser.

Is there a solution out there that can see traffic going to a URL via https and do a lookup on that URL for it in a blacklist, if it is on the list kill the connection to that site. If it is not blacklisted allow the connection thru. I am aware that content filtering https pages would require pointing the browser directly at the filter box instead of doing so transparently.(I don't have the time)

Before you mention AD pushing out the proxy settings. Not all of our machines are windows based. And Most of my users(thank god) are using Firefox. I would like to do this with as little user interaction as possible. Thus the reason I choose a transparent filtering choice to begin with.

Thank you for your time and energy.