ProxySG & Advanced Secure Gateway

 View Only
Expand all | Collapse all

Proxy needs to reauthenticate HTTPS sessions on policy install

  • 1.  Proxy needs to reauthenticate HTTPS sessions on policy install

    Posted Nov 05, 2018 01:39 AM

    Hi Knights

    I'm seeing an issue with ASG policy that I haven't come across before.

    This is an explicit proxy deployment with IWA authentication, category/site based exceptions.  We see that when any policy is saved, any users with active intercepted HTTPS connections are presented with browser authentication popups.  Policy traces show that despite the connection being authenticated at the CONNECT command,  and intercepted requests prior to the policy update being processed against the authenticated user,  following the policy update the requests fail due to authentication required.  The proxy does its best to authenticate by sending a HTTP status 401 (can't do a 407 proxy auth within an existing HTTPS tunnel).  We can prevent the auth popups with some policy to say "do not authenticate SSL proxy requests", but then we need to blow a hole in our policy as we can not have any user based rules applied to HTTPS traffic.

    What makes this environment a bit unusual is that we use multi-tenant policy with 'global' and per-tenant policy,   maybe that triggers the behaviour.

    But,  just wanted to know if any other Knights had seen this sort of behaviour before?

    thanks!

    Simon



  • 2.  RE: Proxy needs to reauthenticate HTTPS sessions on policy install

    Posted Nov 07, 2018 01:14 AM

    Hi Simon,

     

        For an Explicit proxy setup, the response code for Auth should be 407. Now sure where this 401 is coming in from. I have not seen such an issue where the a policy install is throwing authentication prompt to all users. What is your authentication mode in the web auth layer