<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decrytpion not working consistently on MAC's in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decrytpion-not-working-consistently-on-mac-s/m-p/522092#M601</link>
    <description>&lt;P&gt;We just installed SSL decryption ( not self signed) across our PANs. It is working fine with Windows workstations at office and at home. However, with MAC machines it is working inconsistently when at home and&amp;nbsp; connected to global protect.&amp;nbsp; Some sites it's picking up the SSL decryption cert while for others it wasn't. I have already tried to upgrade and downgrade the GP but still no luck.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any recommendation that I should try?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2022 16:33:49 GMT</pubDate>
    <dc:creator>ljovellanos</dc:creator>
    <dc:date>2022-11-22T16:33:49Z</dc:date>
    <item>
      <title>SSL Decrytpion not working consistently on MAC's</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decrytpion-not-working-consistently-on-mac-s/m-p/522092#M601</link>
      <description>&lt;P&gt;We just installed SSL decryption ( not self signed) across our PANs. It is working fine with Windows workstations at office and at home. However, with MAC machines it is working inconsistently when at home and&amp;nbsp; connected to global protect.&amp;nbsp; Some sites it's picking up the SSL decryption cert while for others it wasn't. I have already tried to upgrade and downgrade the GP but still no luck.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any recommendation that I should try?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 16:33:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decrytpion-not-working-consistently-on-mac-s/m-p/522092#M601</guid>
      <dc:creator>ljovellanos</dc:creator>
      <dc:date>2022-11-22T16:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrytpion not working consistently on MAC's</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decrytpion-not-working-consistently-on-mac-s/m-p/522569#M624</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/233662"&gt;@ljovellanos&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Can you describe the problem with bit more information?&lt;/P&gt;
&lt;P&gt;What is the user experience? Does he receive SSL error messages? Or the page is not decrypted?&lt;/P&gt;
&lt;P&gt;Can you provide some screenshots with examples?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version of PanOS are you using?&lt;/P&gt;
&lt;P&gt;Does your GlobalProtect gateway profile for Mac users apply Full tunnel or Split tunnel? Do you have any inclusion/exceptions based on DNS, application or routing?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 10:56:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decrytpion-not-working-consistently-on-mac-s/m-p/522569#M624</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-11-28T10:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrytpion not working consistently on MAC's</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decrytpion-not-working-consistently-on-mac-s/m-p/522640#M625</link>
      <description>&lt;P&gt;Thanks for the response&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I noticed that this only happens with Mac's when they are connected to Global Protect. No issues encountered with Windows machines when using GP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;STRONG&gt;What is the user experience? Does he receive SSL error messages? Or the page is not decrypted?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;--&amp;gt;&amp;nbsp;&lt;/STRONG&gt; I don't see or receive any SSL error message when visiting sites. Most of the sites the I visited were not showing the SSL decryption certificate that I've created. However, there was one site (virustotal) that is using the certificate that I've created. Please see the attached images.&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; it only happens when the machine is connected to the GLobal protect VPN, but when the machine is at the office and connected to the network via LAN or wireless, SSL decryption is working fine, it is using the SSL decryption certificate.&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; I have already tried downgrading or upgrading the GP version on that Mac but got the same problem.&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;--&amp;gt; I have tried different browser as well, but no luck.&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;STRONG&gt;What version of PanOS are you using?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; Im currently testing it on PAN version 9.1.13-h1, but I have also tried on 10.1.5-h2 but got the same behaviour.&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;STRONG&gt;Global protect version&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt;&amp;nbsp; GlobalProtect App Version 6.1.0-58&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; We are using full tunneling when connected to GP.&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;STRONG&gt;Do you have any inclusion/exceptions based on DNS, application or routing?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; none.. it is working fine with Windows machines when connected to GP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 18:41:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decrytpion-not-working-consistently-on-mac-s/m-p/522640#M625</guid>
      <dc:creator>ljovellanos</dc:creator>
      <dc:date>2022-11-28T18:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decrytpion not working consistently on MAC's</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decrytpion-not-working-consistently-on-mac-s/m-p/522666#M627</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/233662"&gt;@ljovellanos&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;If your GP VPN is configured with Full-tunnel mode and there is not domain or application exclusion I would look for issues with GP agent.&lt;/P&gt;
&lt;P&gt;I noticed that you are using Chrome, so I would take a wild guess:&lt;/P&gt;
&lt;P&gt;- Your GP users are allowed to internet with different rules (different from internal users)&lt;/P&gt;
&lt;P&gt;- One of those rules allow GP user to use QUIC. QUIC is proprietary protocol and cannot be decrypted.&lt;/P&gt;
&lt;P&gt;- When users are inside local network they are using different rules, which probably block QUIC and force Chrome to fallback to standard HTTPS, which is being decrypted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should be able to easly confirm or deny my assumption by:&lt;/P&gt;
&lt;P&gt;- Check your traffic logs when Mac is connected to GP and search for (addr.src in &amp;lt;gp-ip-macos&amp;gt;) and (app eq quic). Does your FW block or allow quic?&lt;/P&gt;
&lt;P&gt;- Check your URL logs when Mac is connected to GP. Even without decryption if your Mac is using HTTPS, firewall should be able to inspect the SSL negotiation and create URL log when you try to open facebook or virustotal (or any other site)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe I get your point - you believe that GP is not sending all traffic over the tunnel and that is why it is not being decrypted. Although you could never say there is a wild bug that could cause this, it is easier to confirm some other theories before digging for bugs:&lt;/P&gt;
&lt;P&gt;- Check host routing table while connected to GP, confirm if default is pointing to VPN tunnel.&lt;/P&gt;
&lt;P&gt;- Confirm in the config that there is no exclusion for GP (GP gateway -&amp;gt; Agent -&amp;gt; Setting -&amp;gt; Split tunnel -&amp;gt; Domain and Apps)&lt;/P&gt;
&lt;P&gt;- Try to access a test page that you expect to be decrypted while connected to GP. Check your URL logs, do you see log for that URL? With nslookup resolve the FQDN to IP and try searching this IP in your firewall logs. Do you see any connections on the FW? What application has firewall identified?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 22:01:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-decrytpion-not-working-consistently-on-mac-s/m-p/522666#M627</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-11-28T22:01:28Z</dc:date>
    </item>
  </channel>
</rss>

