O Watchguard tem a inspeção de conteúdo completo HTTPS da mesma forma, instalando um certificado SSL e fazendo um ataque MITM (Man-In-The-Middle) em todo o tráfego, mas pode bloquear nomes de domínio sem recorrer a isso olhando para o campo Indicador do Nome do Servidor enviado pelo navegador para que o servidor possa identificar com qual certificado SSL responder e olhando para o certificado SSL retornado do servidor para ver a quais nomes de domínio ele está assinado.
HTTPS-Proxy: Domain Names
If your Firebox or XTM device runs Fireware XTM v11.9.4 or higher, you can configure your device to allow or deny access to a site, perform content inspection, or bypass content inspection based on the Domain Names rules you create. To match the specified pattern in your Domain Names rules against the name specified in the connection server, the SNI (Server Name Indication), the certificate common name (CN), or the IP address of the server is used.
Because it can determine the actual server name from the HTTPS traffic headers, the SNI is the most accurate option. A certificate CN is often shared between several services from the same site. For example, many Google services such as YouTube and Google Maps share the same certificate CN. If you block access to YouTube based on the certificate CN, access is also blocked to Google Maps and other services with the same CN. The certificate CN is used if the SNI is not available.