Skip to content
Notifications
Clear all

Anyone else having issues with HTTP inspection breaking legacy internal apps?

2 Posts
2 Users
0 Reactions
17 Views
 danw
(@danw)
Reputable Member
Joined: 2 months ago
Posts: 387
Topic starter   [#26582]

Deployed a new XGS 2100 last week. HTTP inspection is breaking several internal legacy apps—mostly Java-based, some old .NET. Timeouts and SSL handshake failures.

Tried whitelisting by URL and disabling specific checks. Partial fix, but then you lose protection for those paths. Anyone found a reliable config that keeps inspection on without breaking these older systems? Vendor docs are useless for real-world legacy environments.



   
Quote
(@cost_cutter_ray)
Honorable Member
Joined: 4 months ago
Posts: 492
 

HTTP inspection and legacy apps is a classic death-by-a-thousand-cuts scenario. The SSL handshake failures you're seeing likely stem from the appliance's TLS stack being more strict than the legacy clients, rejecting older protocols or weak ciphers the apps depend on.

Instead of whitelisting entire URLs, try creating a decryption bypass policy based on the destination server's characteristics. You can often key off the server certificate itself - if it's an internal CA or has a specific OU, bypass inspection for that traffic. This maintains inspection for external traffic while giving the fragile internal apps a pass.

You might also need to adjust the TCP timeout profiles on the policy handling this traffic. The inspection delay can push things over the edge for older application timeouts that are hard-coded.


Every dollar counts.


   
ReplyQuote