https://support.eset.com/kb3560
Issue
- Enable / disable SSL protocol checking
- Add an exception to SSL protocol checking
- A cloud-based service like Dropbox, Google Apps, Quickbooks online or Skype is blocked by ESET SSL scanning
- Wireless devices (printers, scanners, etc.) are blocked by ESET SSL scanning
Solution
I. Enable SSL protocol checking on client workstations from the ESET Remote Administrator Console
- Open the ESET Remote Administrator Console by clicking Start → All Programs → ESET → ESET Remote Administrator Console → ESET Remote Administrator Console.
- Click Tools → Policy Manager.
- Select the policy you want to edit and click Edit Policy.
Figure 1-1
Click the image to view larger in new window - Expand Windows desktop v5 → Personal firewall → Settings → SSL.
- Click SSL protocol checking and select Always scan SSL protocol from the Value drop-down menu.
Figure 1-2
Click the image to view larger in new window - Click Console → Yes to save your changes. Click OK to exit Policy Manager. SSL protocol checking will be enabled on client workstations assigned to this policy the next time they check in to ESET Remote Administrator.
II. Exclude certificates from SSL protocol checking on client workstations from the ESET Remote Administrator Console
- Open the ESET Remote Administrator Console by clicking Start → All Programs → ESET → ESET Remote Administrator Console → ESET Remote Administrator Console.
- Click Tools → Policy Manager.
- Select the policy you want to edit and click Edit Policy.
Figure 2-1
Click the image to view larger in new window - Expand Windows desktop v5 → Personal firewall → Settings → SSL.
- Click SSL protocol checking and select Ask about non-visited sites (exclusions can be set) from the Value drop-down menu.
Figure 2-2
Click the image to view larger in new window - Click Certificate list: See dialog → Edit.
Figure 2-3
Click the image to view larger in new window - In the Certificate list window, select Excluded certificates from the List type drop-down menu and then click Add.
Figure 2-4
- Browse to the certificate (.cer) file you want to exclude, select it and then click Open.
- Click OK to exit the Certificate list window.
- Click Console → Yes to save your changes. Click OK to exit Policy Manager. SSL protocol checking will be enabled on client workstations assigned to this policy the next time they check in to the ESET Remote Administrator.
I. Enable SSL protocol checking on individual client workstations
- Open ESET Endpoint Security or ESET Endpoint Antivirus. How do I open my ESET product?
- Press F5 to access Advanced setup.
- Expand Web and email → Protocol filtering and then click SSL.
- Select Always scan SSL protocol and click OK to save your changes.
Figure 3-1
Click the image to view larger in new window
II. Add an SSL protocol checking exclusion on individual client workstations
- Open ESET Endpoint Security or ESET Endpoint Antivirus. How do I open my ESET product?
- Press F5 to access Advanced setup.
- Expand Web and email → Protocol filtering, click SSL and then select Ask about non-visited sites (exclusions can be set). Click OK.
Figure 3-2
Click the image to view larger in new window - Attempt to access the service or device that is being blocked by ESET (for example, open a web app or attempt to print a file).
- The Encrypted SSL communication dialog will prompt you to select an action to take. Select one of the following to allow the communication (in this example Yes, always is selected):
- Yes, always (recommended): This will allow communication with this service or device at all times, but will still examine the certificate before allowing communications.
- Exclude: This will permanently exclude the certificate from SSL scanning. Communication will always be allowed, but your system may be exposed to threats.
- Yes: This will allow communication with the service or device one time. If you select Yes, you will need to repeat this action the next time that you attempt to access this service or device.
- Yes, always (recommended): This will allow communication with this service or device at all times, but will still examine the certificate before allowing communications.
- Click Yes if you receive a prompt from Windows.
-
Press F5 to access Advanced setup.
-
Expand Web and email → Protocol filtering, click SSL and select Always scan SSL protocol. Once you are finished, click OK to save your changes.
Add a comment
Please log in or register to submit a comment.