<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article How Do I Know if Traffic Is Hitting a Decryption Policy? in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/how-do-i-know-if-traffic-is-hitting-a-decryption-policy/ta-p/514149</link>
    <description>&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;I data-stringify-type="italic"&gt;This article is based on a discussion,&lt;SPAN&gt;&lt;A title=" how can I know that traffic is hitting a configured decryption policy ?" href="https://live.paloaltonetworks.com/t5/general-topics/how-can-i-know-that-traffic-is-hitting-a-configured-decryption/td-p/27841#M106732" target="_blank" rel="noopener"&gt; how can I know that traffic is hitting a configured decryption policy ?&lt;/A&gt;,&lt;/SPAN&gt;&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;&amp;nbsp;posted by&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20013" target="_blank" rel="noopener"&gt;@AKamal&lt;/A&gt;&amp;nbsp;&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;and answered by &lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580" target="_blank" rel="noopener"&gt;@OtakarKlier&lt;/A&gt;, &lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28393" target="_blank" rel="noopener"&gt;@Panos&lt;/A&gt;, &lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5976" target="_blank" rel="noopener"&gt;@VinceM&lt;/A&gt;,&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20889" target="_blank" rel="noopener"&gt;@Sraghunandan&lt;/A&gt; and&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184804" target="_blank" rel="noopener"&gt;@Adrian_Jensen&lt;/A&gt;.&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;&amp;nbsp;Read on to see the discussion and solution!&lt;/I&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;SSL decryption Policy question: How can I know that traffic is hitting a configured decryption policy ?&lt;/P&gt;
&lt;P&gt;There's nothing in the Monitor Tab for decryption policies, nor can I get anything out of the CLI command "show log traffic rule equal DECRYPTION-RULE-NAME"&lt;/P&gt;
&lt;P&gt;Any ideas ?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;UL&gt;
&lt;LI&gt;If traffic hits a rule and is decrypted you can see it from monitor/traffic log inside the Log Details&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1662557896552.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43708i9D858B285091371F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiwi_0-1662557896552.jpeg" alt="kiwi_0-1662557896552.jpeg" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;The following CLI commands are useful too&lt;BR /&gt;&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; show session all 
or
&amp;gt; show session all filter ssl-decrypt yes​&lt;/LI-CODE&gt;
&lt;P&gt;If you see an asterisk under the 'Flag' column that means the session is getting decrypted.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;There are a lot of hidden Columns in the logs. To add them into the view, click one of the column headers and then hover your mouse over the Columns chevron and the display options appear.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1662490849280.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43697i9F9585CFEC5A4991/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1662490849280.png" alt="OtakarKlier_0-1662490849280.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;The ones you will want to have checked are the following:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_1-1662490919616.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43698i163120EA0A6088D4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_1-1662490919616.png" alt="OtakarKlier_1-1662490919616.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;MARK&gt;NOTE: "Decryption Rule" must be a PAN-OS 10.x specific column as it does not show up in PAN-OS 9.x. However, you can test which decryption rule would apply to a given source/destination by using the 'Test Policy Match" tool at the bottom of the Decryption Policy page.&lt;/MARK&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV data-extension-version="1.0.4"&gt;&lt;STRONG&gt;Additional information:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decryption" target="_blank" rel="noopener"&gt;TechDocs: Troubleshoot and Monitor Decryption&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Wed, 07 Sep 2022 20:01:54 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2022-09-07T20:01:54Z</dc:date>
    <item>
      <title>How Do I Know if Traffic Is Hitting a Decryption Policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/how-do-i-know-if-traffic-is-hitting-a-decryption-policy/ta-p/514149</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Sep 2022 20:01:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/how-do-i-know-if-traffic-is-hitting-a-decryption-policy/ta-p/514149</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-09-07T20:01:54Z</dc:date>
    </item>
  </channel>
</rss>

