Overview
Admins should use this traffic redirection method only for trials, pilots, and limited deployments. In most cases, end users can bypass the security and governance that F5 SurePath AI provides with this method. For production deployments, customers should use a redirection method that resists bypass.
Devices accessing GenAI sites through SurePath AI must also install the SurePath AI security certificates. Installing certificates across many devices without automation or an MDM tool is an onerous task.
Prerequisites
SurePath AI Root Certificate (available from the organization's SurePath AI Field CTO)
DNS over HTTPS (DoH) address (in this document)
A web browser that supports DoH. This document uses Google Chrome to demonstrate the configuration.
Procedures
All Operating Systems and Browsers
All operating systems need these files and information.
DoH server URL
Configuration validation page
This site also provides downloads of the SurePath AI security certificates for admins who do not already have them.
Download certificates in different formats
Setup Chrome on Windows
In Google Chrome, select Chrome Menu > Settings
From the left navigation bar select Privacy and security > Security
Turn on Use secure DNS with the toggle
3. Select Add custom DNS service provider from the drop down menu
4. Enter the SurePath DoH server address into the field provided
Install the SurePath Security Certificate on Windows
Press Win + r keys to open the Run dialog
Enter certmgr.msc into the window and press Enter
On the left side select Trusted Root Certificate Authorities
Certificates should now be visible on the right
3. Right Click on Certificates
4. Select All Tasks > Import
5. Click Next until the save dialog appears.
6. Setup is complete. Continue to configuration validation.
Note: Closing Chrome may be required before the certificate takes effect.
Configuration Validation
After completing interception with SASE software or a DoH setup, use the following website to confirm that GenAI traffic passes through the SurePath AI system.
Navigate to https://ready.surepath.ai/
This webpage confirms whether the configuration is correct.
