— a specific URL, such as host.example.com/page.html
Optionally, you can append a port number (for example, example.com:443). If a port
number is not appended, a port number of 443 is assumed.
Note: The sites that typically require exemption are software activation and update sites,
software that validates the site certificate (such as some instant messaging clients and
banking software), and any specific HTTPS sites you do not want scanned.
The following table lists the applications and domains of sites that you should add to the
Sites exempt from HTTPS scanning list in order to make those applications to work
properly for your users.
Domain that must be exemptedIncompatible Application
mozilla.orgFirefox updates
logmeinrescue-enterprise.com and
logmein.com
LogMeIn (used for remote assistance)
<SWAorSMA_hostname>.<your_domain>.<toplevel_domain>Sophos appliance administrative web interface
surgient.comSurgient web site
webex.comWebEx Communications Inc.
sls.microsoft.comWindows Vista activation
loginnet.passport.com and
login.live.com and msn.com
Windows Live Messenger (No exemption is
required for Windows Live Messenger 2009.)
login.yahoo.comYahoo! Messenger
Note: The appliance automatically exempts two sites from HTTPS scanning:webex.com,
which is not compatible with proxies that scan HTTPS content, and the Windows Vista
activation’s site sls.microsoft.com, whose certificate is required by Windows Vista to
complete its activation.
b) Click Add.
The domain or site appears in the Sites exempt from HTTPS scanning list.
c) Click Apply.
■
To remove a site from the exempt sites list, select the check box to the right of that site or
domain, click Delete to remove it from the list, and click Apply.
Sophos Web Appliance | Configuration | 107