Hello,
I have this issue, In the client where I am using a Web prevent server to monitoring traffic and they have 3 bluecoat proxy and a F5 load balancer between the Web prevent Server, weeks ago upgrade to version 14.6 MP1 for the compatibility with the version of SGOS 6.6.x of the proxy.
For do some testing only one of the proxy SG is configured to send the ICAP traffic for dlp server and remove all the categories leaving only 2 web page, dlptest.com and www.fastmail.com, in one computer set the ip of the proxy and create 1 or 2 rules with keywords only but is not creating incident when open the mail via https or http via dlptest.com
Its possible that the F5 still generade a problem?
In the WebPrevent_Access0.log see the traffic for this two page
Is any Troubleshooting possible?
10.99.220.162 "V2luTlQ6Ly9DQVNBX0NFTlRSQUwvQzA1MjA4" 12/jul/2017:15:28:57:365-0300 "GET https://www.fastmail.com/events/ HTTP/1.1" 204 468 """Mozilla/5.0
10.99.220.162 "V2luTlQ6Ly9DQVNBX0NFTlRSQUwvQzA1MjA4" 12/jul/2017:15:31:57:904-0300 "POST https://www.fastmail.com/api/ HTTP/1.1" 204 796 """Mozilla/5.0
10.99.220.162 "V2luTlQ6Ly9DQVNBX0NFTlRSQUwvQzA1MjA4" 12/jul/2017:15:22:33:158-0300 "POST https://dlptest.com/https-post/ HTTP/1.1" 204 6600 """Mozilla/5.0
10.99.220.162 "V2luTlQ6Ly9DQVNBX0NFTlRSQUwvQzA1MjA4" 12/jul/2017:15:22:35:467-0300 "POST https://dlptest.com/https-post/ HTTP/1.1" 204 11988 """Mozilla/5.0