ECH/Cloudflare Edge SWG Status Update

31 days, 2 hours, and 1 minute
Underway
Underway

The scheduled maintenance is now underway. We'll keep you updated on our progress.

Scheduled

Some SSL-secured websites will no longer be TLS decrypted because they don’t match the hostname or category rules in the Edge SWG or Advanced Secure Gateway intercept layer policy due to emerging usage of the ECH (encrypted client hello) standard.

At this time, all ECH enabled websites are Cloudflare-hosted and, according to our data, constitute approximately 3% of all websites on the internet. Websites that adopt ECH present the cloudflare-ech.com hostname to Edge SWG rather than the original hostname such as example.com.

Broadcom has prepared a Tech Note describing how to preserve the visibility required to ensure policy is properly applied in these scenarios. Please review the tech note and contact technical support if you have any questions.

Began at:

Affected components