It Does work by making few changes in SafeSquid policies.
Refinitiv Messenger need to be bypassed from Authentication and HTTPS Inspection to work properly without any interruption.
You can observe below some of the logs of Refinitiv Messenger application.
Code: Select all
"16160588087204941314TxHV" "72049413" "1" "18/Mar/2021:14:43:28" "0" "407" "0" "0" "0" "FALSE" "192.168.51.44" "-" "CONNECT" "connect://redirector.gvt1.com:443/" "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) RefinitivWorkspace/1.3.0 Chrome/85.0.4183.121 Electron/10.1.5-RFV.1 Safari/537.36" "-" "access-restrictions" "Proxy Authentication Required" "192.9.211.6:8080" " TCP_DENIED" "DIRECT" "safesquid" "redirector.gvt1.com" "gvt1.com" "-" "-" "0" "REMOTE TIME" "-" "Unidentified Web2.0 ,Generic Mozilla Browser,Internet Browser" "Unidentified Web2.0,Generic Mozilla Browser,Internet Browser" "computersandsoftware" "" "-" "-"" READ ONLY"
"16160588087204941414TxHV" "72049414" "1" "18/Mar/2021:14:43:28" "1" "403" "0" "0" "0" "FALSE" "192.168.51.44" "-" "CONNECT" "connect://redirector.gvt1.com:443/" "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) RefinitivWorkspace/1.3.0 Chrome/85.0.4183.121 Electron/10.1.5-RFV.1 Safari/537.36" "-" "access-restrictions" "Invalid SSO Auth" "192.9.211.6:8080" "TCP _DENIED" "DIRECT" "safesquid" "redirector.gvt1.com" "gvt1.com" "-" "-" "0" "REMOTE TIME" "-" "Unidentified Web2.0 ,Generic Mozilla Browser,Internet Browser" "Unidentified Web2.0,Generic Mozilla Browser,Internet Browser" "computersandsoftware" "" "-" "-"" READ ONLY"
"16160588277205070514TxHV" "72050705" "1" "18/Mar/2021:14:43:47" "7" "407" "0" "0" "0" "FALSE" "192.168.51.44" "-" "CONNECT" "connect://sts.identity.ciam.refinitiv.net:443/" "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Electron/10.1.5-RFV.1 Safari/537.36 TR-Electron/1.13.283 TR-EikonLight/1.13.413 P-Eikon5/1.13.413 RFV-Electron/1.13.283 RFV-Electron/1.13.283 RFV-Electron/1.13.283 RFV-Workspace/1.13.413" "-" "access-restrictions" "Proxy Authentication Required" "192.9.211.6:8080" "TCP_DENIED" "DIRECT" "safesquid" "sts.identity.ciam.refinitiv.net" "refinitiv.net" "-" "-" "0" "REMOTE TIME" "-" "Unidentified Web2.0 ,Generic Mozilla Browser,Internet Browser" "Unidentified Web2.0,Generic Mozilla Browser,Internet Browser" "COOKIE ALLOW" "" "-" "-" "BYP ASS ELEVATED PRIVACY,LOGIN ALLOWED"
"16160588277205070714TxHV" "72050707" "1" "18/Mar/2021:14:43:47" "8" "403" "0" "0" "0" "FALSE" "192.168.51.44" "-" "CONNECT" "connect://sts.identity.ciam.refinitiv.net:443/" "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Electron/10.1.5-RFV.1 Safari/537.36 TR-Electron/1.13.283 TR-EikonLight/1.13.413 P-Eikon5/1.13.413 RFV-Electron/1.13.283 RFV-Electron/1.13.283 RFV-Electron/1.13.283 RFV-Workspace/1.13.413" "-" "access-restrictions" "Invalid SSO Auth" "192.9.211.6:8080" "TCP_DENIED" "DIRECT" "safesquid" "sts.identity.ciam.refinitiv.net" "refinitiv.net" "-" "-" "0" "REMOTE TIME" "-" "Unidentified Web2.0,Generic Mozilla Browser,Internet Browser" "Unidentified Web2.0,Generic Mozilla Browser,Internet Browser" "COOKIE ALLOW" "" "-" "-" "BYPASS ELEVATED PRIVACY,LOGIN ALLOWED"
"16160591467207998514TxHV" "72079985" "1" "18/Mar/2021:14:49:07" "870" "407" "0" "0" "0" "FALSE" "192.168.51.44" "-" "CONNECT" "connect://apac1-gateway.platform.refinitiv.com:443/" "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Electron/10.1.5-RFV.1 Safari/537.36 TR-Electron/1.13.283 TR-EikonLight/1.13.413 P-Eikon5/1.13.413 RFV-Electron/1.13.283 RFV-Electron/1.13.283 RFV-Workspace/1.13.413" "-" "access-restrictions" "Proxy Authentication Required" "192.9.211.6:8080" "TCP_DENIED" "DIRECT" "safesquid" "apac1-gateway.platform.refinitiv.com" "refinitiv.com" "-" "-" "0" "REMOTE TIME" "-" "Unidentified Web2.0,Generic Mozilla Browser ,Internet Browser" "Unidentified Web2.0,Generic Mozilla Browser,Internet Browser" "computersandsoftware" "" "-" "-" "READ ONLY"
"16160591477208012714TxHV" "72080127" "1" "18/Mar/2021:14:49:07" "5" "403" "0" "0" "0" "FALSE" "192.168.51.44" "-" "CONNECT" "connect://apac1-gateway.platform.refinitiv.com:443/" "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Electron/10.1.5-RFV.1 Safari/537.36 TR-Electron/1.13.283 TR-EikonLight/1.13.413 P-Eikon5/1.13.413 RFV-Electron/1.13.283 RFV-Electron/1.13.283 RFV-Workspace/1.13.413" "-" "access-restrictions" "Invalid SSO Auth" "192.9.211.6:8080" "TCP_DENIED" "DIRECT" "safesquid"" apac1-gateway.platform.refinitiv.com" "refinitiv.com" "-" "-" "0" "REMOTE TIME" "-" "Unidentified Web2.0,Generic Mozilla Browser,Interne t Browser" "Unidentified Web2.0,Generic Mozilla Browser,Internet Browser" "computersandsoftware" "" "-" "-" "READ ONLY"
There were many domains provided by Refinitiv Messenger application team's document. All those domains cannot be allowed as per the policy.
So by observing the logs we have created a policy based on User Agent: RefinitivWorkspace, RFV-Workspace to be bypassed.
You can add a policy in Request Profiles and link it with Access Profiles to allow.
Request Profiles
- Added Refinitiv Messenger User Agent in Request Profiles.
- RFV1.png (29.86 KiB) Viewed 1647 times
Access Profiles
- Linked Refinitiv Messenger Request Profiles with Access Profiles.
- RFV2.png (45.86 KiB) Viewed 1647 times
By adding the above policy, Refinitiv Messenger Application will work.