<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exclude a Application behind Clientless VPN from decryption in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/exclude-a-application-behind-clientless-vpn-from-decryption/m-p/556160#M4347</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41971"&gt;@Martin.Shemon&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The NGFW will decrypt clientless VPN because it is designed to do so.&amp;nbsp; The client creates an SSL session to the NGFW, and it creates a new SSL session to the internal server.&amp;nbsp; This happens even if you do not have decryption enabled.&amp;nbsp; It is, essentially, a man-in-the-middle.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have 2 solutions, in my opinion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Fix the decryption issue.&amp;nbsp; For example, if you put the IP address in the Hostname field of the General tab and your certificate does not have the IP address in it, you will get decryption errors.&amp;nbsp; Many times the issue will come down to supported and non-supported technologies.&amp;nbsp; Please see the links below.&lt;/LI&gt;
&lt;LI&gt;Use the GlobalProtect client.&amp;nbsp; That traffic will abide by the decryption policy and can be excluded.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-clientless-vpn/supported-technologies" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-clientless-vpn/supported-technologies&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-clientless-vpn/supported-technologies" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-clientless-vpn/supported-technologies&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Fri, 01 Sep 2023 15:28:48 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-09-01T15:28:48Z</dc:date>
    <item>
      <title>Exclude a Application behind Clientless VPN from decryption</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/exclude-a-application-behind-clientless-vpn-from-decryption/m-p/556136#M4346</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am currently facing the problem of publishing an internal web application via GlobalProtect Portal and Clientless VPN.&lt;/P&gt;
&lt;P&gt;The principle is already used by us and works very well so far.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, this one particular application has a property that makes SSL decryption impossible. With "normal" SSL decryption, you can either set a no-decrypt policy or a general exclusion from decryption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I cannot find such a possibility for Clientless VPN and the normal exclusions do not work either. Without such an exclusion, however, the internal application cannot be published.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also debugged, why the ssl inspection is not working, found the reason (Handshake, renegotiation) and found out that it is not possible to get this to work, it depends on the application itself, which i cant change.&lt;/P&gt;
&lt;P&gt;What am I missing or what other possibilities exist that I may not know about?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many greetings&lt;BR /&gt;Martin&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 13:02:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/exclude-a-application-behind-clientless-vpn-from-decryption/m-p/556136#M4346</guid>
      <dc:creator>Martin.Shemon</dc:creator>
      <dc:date>2023-09-01T13:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude a Application behind Clientless VPN from decryption</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/exclude-a-application-behind-clientless-vpn-from-decryption/m-p/556160#M4347</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41971"&gt;@Martin.Shemon&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The NGFW will decrypt clientless VPN because it is designed to do so.&amp;nbsp; The client creates an SSL session to the NGFW, and it creates a new SSL session to the internal server.&amp;nbsp; This happens even if you do not have decryption enabled.&amp;nbsp; It is, essentially, a man-in-the-middle.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have 2 solutions, in my opinion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Fix the decryption issue.&amp;nbsp; For example, if you put the IP address in the Hostname field of the General tab and your certificate does not have the IP address in it, you will get decryption errors.&amp;nbsp; Many times the issue will come down to supported and non-supported technologies.&amp;nbsp; Please see the links below.&lt;/LI&gt;
&lt;LI&gt;Use the GlobalProtect client.&amp;nbsp; That traffic will abide by the decryption policy and can be excluded.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-clientless-vpn/supported-technologies" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-clientless-vpn/supported-technologies&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-clientless-vpn/supported-technologies" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-clientless-vpn/supported-technologies&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 15:28:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/exclude-a-application-behind-clientless-vpn-from-decryption/m-p/556160#M4347</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-01T15:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude a Application behind Clientless VPN from decryption</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/exclude-a-application-behind-clientless-vpn-from-decryption/m-p/556185#M4348</link>
      <description>&lt;P&gt;Hi Tom,&lt;BR /&gt;&lt;BR /&gt;thanks for the Hints !&amp;nbsp;&amp;nbsp;&lt;BR /&gt;In this special case it is not possible to fix the decryption error, it depends on the application itself. After some deep debugging if found out that the Client Handshake breaks the SSL Decryption. I also found a PaloAlto article which describes that it is not resolvable.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POJ0CAO&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POJ0CAO&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;This is why i asked for a decryption exclusion.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I understand that it is not possible to exclude this special single host, so i have to find other solutions.&lt;BR /&gt;I now try to publish this application via a Global Protect Connection with a split tunnel configuration only for this single app.&lt;BR /&gt;&lt;BR /&gt;If you or somebody has annother idea how to prevent decryption, it would be great, cause this is the prefered way.&lt;BR /&gt;&lt;BR /&gt;Many Thanks and have a great weekend.&lt;BR /&gt;Martin&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 17:51:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/exclude-a-application-behind-clientless-vpn-from-decryption/m-p/556185#M4348</guid>
      <dc:creator>Martin.Shemon</dc:creator>
      <dc:date>2023-09-01T17:51:47Z</dc:date>
    </item>
  </channel>
</rss>

