Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    E2Guardian: Failed to negotiate ssl connection to client

    Scheduled Pinned Locked Moved Cache/Proxy
    12 Posts 4 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      ravegen
      last edited by

      I wanted to show the access log showing Dropbox connection was dropped.

      https://client.dropbox.com DENIED Failed to negotiate ssl connection to client - 0 0 SSL SITE 4 403
      https://d.dropbox.com DENIED Failed to negotiate ssl connection to client - 0 0 SSL SITE 4 403

      I have already installed the CA on the client browser.  But I do not know why it is failing to negotiate ssl connection.
      I have place the CA in the Trusted Root Certificate Authority in internet explorer and chrome. And in Mozilla, in the section Settings\Certificate\Import of Mozilla.  Is there other proper place where Dropbox and Yahoo Messenger reads this CA certificate ?

      Any thoughts Marcelloc ?

      1 Reply Last reply Reply Quote 0
      • S Offline
        susamlicubuk
        last edited by

        Create a new alias in the firewall + alias section
        into
        Add your bypass domains like d.dropbox.com, client.dropbox.com
        then this alias is the name
        Bypass Proxy for These Destination IPs
        Write to section
        this is how I work using dropbox

        1 Reply Last reply Reply Quote 0
        • R Offline
          ravegen
          last edited by

          @susamlicubuk:

          Create a new alias in the firewall + alias section
          into
          Add your bypass domains like d.dropbox.com, client.dropbox.com
          then this alias is the name
          Bypass Proxy for These Destination IPs
          Write to section
          this is how I work using dropbox

          can I use *.dropbox.com instead of specifying the subdomain ?

          1 Reply Last reply Reply Quote 0
          • S Offline
            susamlicubuk
            last edited by

            @ravegen:

            @susamlicubuk:

            Create a new alias in the firewall + alias section
            into
            Add your bypass domains like d.dropbox.com, client.dropbox.com
            then this alias is the name
            Bypass Proxy for These Destination IPs
            Write to section
            this is how I work using dropbox

            can I use *.dropbox.com instead of specifying the subdomain ?

            no but
            It would be better if there was another partition to do the ssl bypass and if the domains could be written
            because it is a bit unstable when you add the alias section
            marcello maybe can.

            1 Reply Last reply Reply Quote 0
            • R Offline
              ravegen
              last edited by

              What is the relationship of adding Pass Rule in the firewall for that sites while I am using E2Guardian for filtering ?

              1 Reply Last reply Reply Quote 0
              • S Offline
                susamlicubuk
                last edited by

                You are bypassing e2Guardian because ssl is a filtering problem
                e2Guardian with firewall rule is very different things
                e2Guardian squidGuard alternative content filter software
                and much faster

                1 Reply Last reply Reply Quote 0
                • R Offline
                  ravegen
                  last edited by

                  ok.  so d.dropbox.com, client.dropbox.com is already known as you gave it to me.  but what about other sites that our 3rd party application use.  How will I know them ?

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    susamlicubuk
                    last edited by

                    I see and bypass the access log
                    Why do you want the ssl filter so much
                    I do not install SSL certificates in some institutions
                    It can make very stable filter while loading (http and https)
                    only in the https sites are banned warning does not come

                    1 Reply Last reply Reply Quote 0
                    • marcellocM Offline
                      marcelloc
                      last edited by

                      e2guardian can only intercept https sites but some applications like dropbox and skype user same port 443 but with another protocol(most proprietary).

                      That's why you can't intercept it. You can try to include skype.com and dropbox.com on e2guardian exception list to do not intercept these connections or add on firewall alias like susamlicubuk posted.

                      Treinamentos de Elite: http://sys-squad.com

                      Help a community developer! ;D

                      1 Reply Last reply Reply Quote 0
                      • P Offline
                        pfsensation
                        last edited by

                        @marcelloc:

                        e2guardian can only intercept https sites but some applications like dropbox and skype user same port 443 but with another protocol(most proprietary).

                        That's why you can't intercept it. You can try to include skype.com and dropbox.com on e2guardian exception list to do not intercept these connections or add on firewall alias like susamlicubuk posted.

                        Its SSL pinning, the developers of these programs bake the CA cert into the program so that fake certs like the ones from E2 Guardian cannot be used to intercept traffic.

                        1 Reply Last reply Reply Quote 0
                        • R Offline
                          ravegen
                          last edited by

                          so to block dropbox, skype, yahoo messenger is to mitm ssl disrupting connection and to allow them under mitm ssl connection is to place them on exemption, right?

                          1 Reply Last reply Reply Quote 0
                          • P Offline
                            pfsensation
                            last edited by

                            @ravegen:

                            so to block dropbox, skype, yahoo messenger is to mitm ssl disrupting connection and to allow them under mitm ssl connection is to place them on exemption, right?

                            Pretty much, yes. Although if you completely want to block them, use banned list and don't rely on the SSL pinning to block it as the developers of the platform can change things.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.