<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic Decryption sources in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586179#M3163</link>
    <description>&lt;P&gt;Thanks for the Reply,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was thinking of using user-id's but was not sure if that was supported. so, I would just add the AD group to 'group mapping' under 'user identification' than apply the group to the decryption policy?&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2024 13:59:59 GMT</pubDate>
    <dc:creator>MNoble</dc:creator>
    <dc:date>2024-05-08T13:59:59Z</dc:date>
    <item>
      <title>Dynamic Decryption sources</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586031#M3130</link>
      <description>&lt;P&gt;Hello all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are slowly rolling out Decryption to folks and was wondering if there is a way to dynamically add users, similar to user-ID.&lt;/P&gt;
&lt;P&gt;My current way is manually adding computer objects which was fine for the first 15 computers but is starting to get tedious.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know I can import objects using the API but am looking for a more dynamic method.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 16:17:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586031#M3130</guid>
      <dc:creator>MNoble</dc:creator>
      <dc:date>2024-05-07T16:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Decryption sources</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586039#M3131</link>
      <description>&lt;P&gt;Hello friend!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think your requirement might be solved using Dynamic User Groups, you can find more information in:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/use-dynamic-user-groups-in-policy" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/use-dynamic-user-groups-in-policy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mark my comment as solved if you think it solved your doubt,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 16:37:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586039#M3131</guid>
      <dc:creator>jfernandez1</dc:creator>
      <dc:date>2024-05-07T16:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Decryption sources</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586051#M3134</link>
      <description>&lt;P&gt;Thanks for Reply, I would still need to manually enter objects. Also, I think Dynamic user Groups use Tags for filtering which is not what I'm looking for.&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 17:36:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586051#M3134</guid>
      <dc:creator>MNoble</dc:creator>
      <dc:date>2024-05-07T17:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Decryption sources</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586059#M3135</link>
      <description>&lt;P&gt;Not sure there is a more automated way to achieve this outside of API. You could use Terraform to add objects on the fly from an excel spread sheet if you knew how to do that. Also why not just use user-id for the decryption policy and make an AD group for "Decryption_Users" and add the users to that group which would then hit the policy?&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 18:33:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586059#M3135</guid>
      <dc:creator>S_Williams901</dc:creator>
      <dc:date>2024-05-07T18:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Decryption sources</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586088#M3143</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Two ways I can think of to achieve this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;User-id&lt;/P&gt;
&lt;P&gt;If you have user-id setup with active directory, the use of this can be the solution you are looking for. Create a group and add that group to your decryption policy. That way when you add users to this group in AD, it will propagate to the PAN and their traffic will hit the decrypt policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source IP's&lt;/P&gt;
&lt;P&gt;Use the source IP's of subnets, single addresses, or a group of addresses and add them to the decryption policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 20:55:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586088#M3143</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-05-07T20:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Decryption sources</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586179#M3163</link>
      <description>&lt;P&gt;Thanks for the Reply,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was thinking of using user-id's but was not sure if that was supported. so, I would just add the AD group to 'group mapping' under 'user identification' than apply the group to the decryption policy?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:59:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586179#M3163</guid>
      <dc:creator>MNoble</dc:creator>
      <dc:date>2024-05-08T13:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Decryption sources</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586180#M3164</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Exactly, its that simple. Just remember that its not instant from when you add someone to the group and it starts decrypting. The PAN needs to update the AD group, used to be 60 minutes by default. But can be changed to meet your needs.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRyCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRyCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 14:09:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586180#M3164</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-05-08T14:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Decryption sources</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586181#M3165</link>
      <description>&lt;P&gt;Thanks again! Marked as Solution &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 14:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586181#M3165</guid>
      <dc:creator>MNoble</dc:creator>
      <dc:date>2024-05-08T14:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Decryption sources</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586183#M3166</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Best of luck! If you have additional questions, feel free to post. We are here to help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 14:13:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-decryption-sources/m-p/586183#M3166</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-05-08T14:13:56Z</dc:date>
    </item>
  </channel>
</rss>

