Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Zenarmor (Sensei)
»
TLS/SSL Inspection is now going to be business license only?
« previous
next »
Print
Pages: [
1
]
2
Author
Topic: TLS/SSL Inspection is now going to be business license only? (Read 4622 times)
Vilmalith
Newbie
Posts: 18
Karma: 0
TLS/SSL Inspection is now going to be business license only?
«
on:
March 09, 2023, 04:24:05 pm »
TLS/SSL Inspection is now going to be business license only?
I noticed today that your features list, lists Policy based Transparent TSL/SSL Inspection as coming soon only for the Business license. Granted I haven't looked at the feature list in awhile. But the feature list doesn't list any other TLS/SSL inspection. Are none of the other licenses for Zenarmor getting TLS/SSL inspection now?
Logged
NW4FUN
Full Member
Posts: 114
Karma: 1
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #1 on:
March 13, 2023, 05:33:09 pm »
Apparently yes, they've decided for whatever reason to only enable that feature on the business subscription, leaving out the HOME subscribers...
I'm very UPSET with that direction as it leaves my personal use case uncovered. I hope they'd change their mind...
Logged
chemlud
Hero Member
Posts: 2485
Karma: 112
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #2 on:
March 13, 2023, 05:38:49 pm »
What did you except? Lock in - then cash time. Bussiness as usual...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare
felix eichhorns premium katzenfutter mit der extraportion energie
A router is not a switch - A router is not a switch - A router is not a switch - A rou....
athurdent
Sr. Member
Posts: 251
Karma: 23
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #3 on:
March 13, 2023, 05:52:36 pm »
According to the archived 04/2020 version of the plan comparison, Policy based Transparent TLS/SSL Inspection has never been announced as a part of any other than the business plan, at least not in the past years.
https://web.archive.org/web/20200427221415/https://www.sunnyvalley.io/plans/
Logged
NW4FUN
Full Member
Posts: 114
Karma: 1
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #4 on:
March 15, 2023, 11:28:58 am »
@athurdent and @chemlud
That's not the point. Not providing Full TLS Inspection to HOME subscribers is a huge mistake as that covers more than a use case for the average household. Limiting that feature offering to BUSINESS only ($80/m) makes it just not an option for home users who are paying $99/year for their subscription.
Honestly, missing out on that makes me questioning the entire HOME subscription plan...is it still worth it considering pretty much ALL traffic is encrypted these days?
Other vendors I've been using in the past with a HOME/FAMILY plan (Untangle is a great example but not the only one) before migrating to OPNsense, DO offer TLS inspection functionality. Actually their HOME plan is basically a full BUSINESS plan offered at an affordable price for home/personal usage.
Shame on you Sunnyvalley if you're reading this!
/rant
Logged
athurdent
Sr. Member
Posts: 251
Karma: 23
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #5 on:
March 15, 2023, 01:11:27 pm »
I am happy without TLS decryption for home. DPI/app/services/URL recognition works pretty well with Zenarmor, and lets me block the bad ones.
Having implemented SSL decryption at work with different vendors, it's no fun. You end up with a larger exception list than you wanted. SSL generally does not like to be man-in-the-middled, plus there are a lot of apps that come with pinned CAs, won't respect your private issuing CA and will break.
Logged
NW4FUN
Full Member
Posts: 114
Karma: 1
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #6 on:
March 15, 2023, 01:54:42 pm »
I agree the TLS inspection is a pain generally speaking, however, the fact YOU are happy without it, it doesn't necessarily mean it's either not needed or nobody wants it.
There's a plethora of use cases for which it is a must have scenario. Moreover, on a policy based TLS, you can easily contain the inspection to what you really need to control/block (nobody is looking to inspect ALL the encrypted traffic - that's a nonsense).
Logged
beki
Jr. Member
Posts: 93
Karma: 10
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #7 on:
March 16, 2023, 02:28:54 pm »
Hi all!
Just wanted to let you know that Zenarmor offers free Domain and IP-based Certificate TLS inspection for every packet, whether you're using Free, Home, SOHO, or Business edition.
If you're using the Business edition, you will also take advantage of the Full TLS inspection feature.
Let us know if you have any questions or need further assistance.
Best
Logged
NW4FUN
Full Member
Posts: 114
Karma: 1
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #8 on:
March 17, 2023, 07:05:16 am »
Can you please elaborate on the differences between the two offered levels of TLS inspection?
Logged
beki
Jr. Member
Posts: 93
Karma: 10
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #9 on:
March 17, 2023, 02:51:06 pm »
Hi NW4FUN,
Free/Certificate TLS inspection can block/allow according to the domain name.
But, Full TLS inspection can screen all data packets. For example, it can block/allow traffic by checking not only the domain name but also the URL. Malicious file protection and antivirus protection will work based on Full TLS inspection capability as well.
Best
Logged
NW4FUN
Full Member
Posts: 114
Karma: 1
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #10 on:
March 20, 2023, 08:57:20 am »
Thanks! That might actually do for my use case…
How do I configure the free TLS inspection? I simply download and install the Zenarmor certificate onto the impacted devices?
Thanks for your guidance and support
Logged
beki
Jr. Member
Posts: 93
Karma: 10
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #11 on:
March 20, 2023, 02:03:42 pm »
There is no special configuration for free TLS inspection.
After defining the default policy, it will automatically apply tls inspection.
Logged
NW4FUN
Full Member
Posts: 114
Karma: 1
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #12 on:
March 21, 2023, 08:18:28 am »
There’s something odd then going on…for instance, Zenarmor is unable to read TikTok.com or Snapchat.com and block it accordingly (social network category is restricted), whilst it is able to restrict the app itself (I guess it can successfully read the apps signature).
Can you please advise
Logged
beki
Jr. Member
Posts: 93
Karma: 10
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #13 on:
March 21, 2023, 01:54:55 pm »
Thanks for your feedback.
Snapchat looks under the IM app category. We will move it to the social media category.
Tiktok should be blocked. Are you using TikTok mobile app or trying to access it via a web browser on a desktop?
Logged
NW4FUN
Full Member
Posts: 114
Karma: 1
Re: TLS/SSL Inspection is now going to be business license only?
«
Reply #14 on:
March 21, 2023, 05:27:36 pm »
They're both restricted in the WEB CONTROLS and the APP CONTROLS sections.
Whilst the APPs itself are being blocked, same is not the case for when accessing from web browser (SAFARI)
Logged
Print
Pages: [
1
]
2
« previous
next »
OPNsense Forum
»
English Forums
»
Zenarmor (Sensei)
»
TLS/SSL Inspection is now going to be business license only?