How to Exclude Gmail (mail.google.com) from DPI-SSL Client Inspection

Description

Google uses a single wildcard certificate with a CN of *.google.com for all their services like YouTube.com, Google.com etc. The individual domain names are present in the Subject Alt Name (SAN) field of the certificate. Due to this, in previous deployments of DPI-SSL, it was not possible to include or exclude an individual domain from DPI-SSL inspection. 

In SonicOS 6.2.5.x firmware, with its DPI-SSL enhancements, it is now possible to exclude or include domains using either the Server Name present in the Server Name Indication (SNI) of the Client Hello or by domain names present in the SAN extension of the Certificate. 

This KB article describes how to exclude Gmail.com (mail.google.com) from DPI-SSL inspection without affecting content decryption and inspection of other Google services. 

Resolution

Here's how to add Google Domains to the DPI-SSL Exclusions:

  1. Log in to the SonicWall GUI
  2. Go to the Manage tab
  3. Go to Deep Packet Inspection | SSL Client Deployment
  4. Navigate to the Common Name tab
  5. Click on Add
  6. Enter the following Common Names:
    • googleuser.content.com
    • accounts.youtube.com
    • accounts.google.com
    • mail.google.com
    • www.gmail.com
    • gstatic.com 
    • googleusercontent.com
  7. Set Action to Exclude
  8. Click on OK

Image

Testing

From a host behind the SonicWall, go to gmail.com or mail.google.com. The site must show its certificate as issued by a public CA.

Related Articles

  • What wireless cards and USB broadband modems are supported on firewalls and access points?
    Read More
  • How to export and import connection profiles in NetExtender
    Read More
  • Unable access High availability idle device using monitoring IP address
    Read More
not finding your answers?
was this article helpful?