Good afternoon, thank you for your time and good vibes.
I have the following situation:
We know that by default at Global level, Netskope, is blocking sites with self signed certificates.
In certain cases there are sites we say "known" somewhat controlled, where there are VPN access portals, sites or systems with self-signed certificates, etc..
Now the idea is not to apply it globally, but by means of exceptions, so as not to allow all sites with self-signed certificates, but only some based on need and demand.
Then I tried to apply a web policy, with action Bypass and it did not work, it still shows the blocking of sites with self signed certificate, as I did not intend to allow it globally, I added a policy, of SSL decrypt, to not make decrypt to a custom web category, that contains these sites, to omit or bypass the blocking. Well this worked, but with this I feel that we lose visibility and inspection to these sites, therefore, please clarify what is the position, recommendation, procedure, from Netskope to apply this type of exceptions, for sites with self-signed certificates, without the need to adjust globally, the bypass that would apply to all, but to be in a controlled and specific way.
I remain attentive
Thank you
Best regards