<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decryption exception issue - no SNI - SCN: chat.signal.org in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-exception-issue-no-sni-scn-chat-signal-org/m-p/508214#M200</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/212680"&gt;@JarerkZajac&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;You can create Decryption rule, matching by destination address and using FQDN object with action set to "no decrypt"&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jul 2022 12:41:39 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2022-07-07T12:41:39Z</dc:date>
    <item>
      <title>Decryption exception issue - no SNI - SCN: chat.signal.org</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-exception-issue-no-sni-scn-chat-signal-org/m-p/505780#M179</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;how to add following decryption error (ssl-forward-proxy) to exceptions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- logs-&amp;gt;decryption: dest address: ac88393aca5853df7.awsglobalaccelerator.com (shodan solves this ip /13.248.212.111/ also to service.signal.org; SNI - no value; SCN: chat.signal.org; error: General TLS protocol error&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JarerkZajac_0-1655994017023.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41933i230EFECA928AFD86/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JarerkZajac_0-1655994017023.png" alt="JarerkZajac_0-1655994017023.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JarerkZajac_3-1655994196320.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41936i6EC6DAEF71F9932C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JarerkZajac_3-1655994196320.png" alt="JarerkZajac_3-1655994196320.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- logs-&amp;gt;traffic: destination like above; decrypted: no; app: ssl; session end reason: decrypt-cert-validation; action: allow; type: end&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JarerkZajac_1-1655994083091.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41934i0D6E7DDA2A01F714/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JarerkZajac_1-1655994083091.png" alt="JarerkZajac_1-1655994083091.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I have done:&lt;/P&gt;&lt;P&gt;- device-&amp;gt;cert management-&amp;gt;SSL decrypt exclusion: chat.signal.org and *.signal.org -&amp;gt; exclude from decryption&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JarerkZajac_2-1655994143220.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41935i0027359EC78E08D9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JarerkZajac_2-1655994143220.png" alt="JarerkZajac_2-1655994143220.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other (almost all) exceptions work fine, but only this cert has no value for SNI (Server Name Indication).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JarerkZajac_7-1655994370894.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41940iF3C8BFF298942B68/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JarerkZajac_7-1655994370894.png" alt="JarerkZajac_7-1655994370894.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 14:26:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-exception-issue-no-sni-scn-chat-signal-org/m-p/505780#M179</guid>
      <dc:creator>JarerkZajac</dc:creator>
      <dc:date>2022-06-23T14:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption exception issue - no SNI - SCN: chat.signal.org</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-exception-issue-no-sni-scn-chat-signal-org/m-p/508214#M200</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/212680"&gt;@JarerkZajac&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;You can create Decryption rule, matching by destination address and using FQDN object with action set to "no decrypt"&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 12:41:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-exception-issue-no-sni-scn-chat-signal-org/m-p/508214#M200</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-07-07T12:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption exception issue - no SNI - SCN: chat.signal.org</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-exception-issue-no-sni-scn-chat-signal-org/m-p/527691#M781</link>
      <description>&lt;P&gt;Hi Astardzhiev,&lt;/P&gt;
&lt;P&gt;thank you for answer and apologise for late reply. I solved this problem by adding FQDN to URL custom category and using it in decryption rule as no decrypt url category.&lt;/P&gt;
&lt;P&gt;Chat.signal works fine, but lately another: signal messenger started the same -&amp;gt; no SNI, no SCN (subject common name), at the same IP/FQDN address. So I added new decrypt rule and added this address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you again for reply and solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jarek&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 10:16:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-exception-issue-no-sni-scn-chat-signal-org/m-p/527691#M781</guid>
      <dc:creator>JarerkZajac</dc:creator>
      <dc:date>2023-01-19T10:16:36Z</dc:date>
    </item>
  </channel>
</rss>

