Sophos UTM IconI am currently implementing Sophos UTM and I quite like this solution. It is free up for home usage and can easily be installed on a hypervisor.

I wanted to scan encrypted traffic (ssl) as well so I activated the "Decrypt and scan" option:

image

When testing this on one of my iPad’s I noticed that the App Store didn’t work properly anymore.

When I tried to update applications I got the following error: "Cannot connect to iTunes Store". Additionally when I searched for Apps the search would return no results.

To fix this go to Web Protection | Filtering Options and click Edit on the "Apple Update" item:

image

In the "For all request" section add the following Target Domain rule:

^https?://([A-Za-z0-9.-]*\.)?apple.com

For all requests | Matching these URLs | Target Domains

This was tested on Sophos UTM with firmware version 9.201-25 in Transparent Mode.