DPI-SSL inspection and UniFi equipment
HIS_Daniel
Enthusiast ✭✭
Hello,
I recently installed a new TZ570 at a customer site along with some UniFi AP's and a Cloud Key. With DPI-SSL enabled, the access points were not able to be adopted by the UBNT Cloud Key. I disabled DPI-SSL inspection and we were then able to adopt the AP's and finish configuring them. Once we adopted them, we set static ip's for all Ubiquiti equipment. I would like to re-enable DPI-SSL as quick as possible and am trying to pick the best course of action. Should I :
- Add the Ubiquiti equipment by their static ip addresses to a DPI-SSL exclusion Address Group?
- Add the UBNT common name, network.unifi.ui.com, to the list of DPI-SSL exclusions?
- Both?
Thank you,
Category: Entry Level Firewalls
0
Best Answer
-
BWC Cybersecurity Overlord ✭✭✭
Hi @HIS_Daniel
I guess I would go with the Address Group just in case the common name changes over time.
--Michael@BWC
5
Answers
@HIS_Daniel,
It would be best to go with Option 1 as suggested by @BWC. The common name might change or there might be dependencies on other common names, so it would be ideal to exclude the address object.
Thanks!
Shipra Sahu
Technical Support Advisor, Premier Services
Hello @BWC and @shiprasahu93
Thank you for the replies. I figured that was the best way to go, just wanted some confirmation.
Thank you again!