<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Detect RC4 traffic in Strata Logging Service Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/strata-logging-service/detect-rc4-traffic/m-p/1244087#M300</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1081569299"&gt;@PMorendage&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can identify weak ciphers with a decryption profile for non-decrypted traffic.&amp;nbsp; Create a decryption rule with the action of no-decrypt and assign the decryption profile to it.&amp;nbsp; Since you do not want to block weak ciphers at this time, allow everything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/decryption-profile#create-a-decryption-profile-pm" target="_blank"&gt;https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/decryption-profile#create-a-decryption-profile-pm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When a lot of traffic runs through the decryption profile, you can use cool tools to analyze the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/decryption/administration/troubleshooting-decryption/identify-weak-tls-protocols-cipher-suites#identify-weak-tls-protocols-and-cipher-suites-pan-os" target="_blank"&gt;https://docs.paloaltonetworks.com/network-security/decryption/administration/troubleshooting-decryption/identify-weak-tls-protocols-cipher-suites#identify-weak-tls-protocols-and-cipher-suites-pan-os&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you have analyzed the traffic, you can choose to block weak certificates, ciphers, or protocols by unchecking the boxes in the decryption profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 17 Dec 2025 22:15:44 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2025-12-17T22:15:44Z</dc:date>
    <item>
      <title>Detect RC4 traffic</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/detect-rc4-traffic/m-p/1244034#M299</link>
      <description>&lt;P data-start="75" data-end="183"&gt;How do we detect RC4 traffic without decrypting using the Palo Alto toolset (NGFW, SCM, SLS, IoT, etc.)?&lt;/P&gt;
&lt;P data-start="188" data-end="227"&gt;In SLS, I can currently filter down to:&lt;/P&gt;
&lt;P data-start="232" data-end="316"&gt;&lt;CODE data-start="232" data-end="316"&gt;Application Subcategory = 'auth-service' AND Application = 'active-directory-base'&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-start="321" data-end="397"&gt;However, there is no option to identify the use of weak ciphers (e.g., RC4).&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 05:35:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/detect-rc4-traffic/m-p/1244034#M299</guid>
      <dc:creator>PMorendage</dc:creator>
      <dc:date>2025-12-17T05:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Detect RC4 traffic</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/detect-rc4-traffic/m-p/1244087#M300</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1081569299"&gt;@PMorendage&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can identify weak ciphers with a decryption profile for non-decrypted traffic.&amp;nbsp; Create a decryption rule with the action of no-decrypt and assign the decryption profile to it.&amp;nbsp; Since you do not want to block weak ciphers at this time, allow everything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/decryption-profile#create-a-decryption-profile-pm" target="_blank"&gt;https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/decryption-profile#create-a-decryption-profile-pm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When a lot of traffic runs through the decryption profile, you can use cool tools to analyze the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/decryption/administration/troubleshooting-decryption/identify-weak-tls-protocols-cipher-suites#identify-weak-tls-protocols-and-cipher-suites-pan-os" target="_blank"&gt;https://docs.paloaltonetworks.com/network-security/decryption/administration/troubleshooting-decryption/identify-weak-tls-protocols-cipher-suites#identify-weak-tls-protocols-and-cipher-suites-pan-os&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you have analyzed the traffic, you can choose to block weak certificates, ciphers, or protocols by unchecking the boxes in the decryption profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 22:15:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/detect-rc4-traffic/m-p/1244087#M300</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-12-17T22:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Detect RC4 traffic</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/detect-rc4-traffic/m-p/1244101#M301</link>
      <description>&lt;P&gt;Thank you very much Tom , Let me test and get back to you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2025 02:00:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/detect-rc4-traffic/m-p/1244101#M301</guid>
      <dc:creator>PMorendage</dc:creator>
      <dc:date>2025-12-18T02:00:22Z</dc:date>
    </item>
  </channel>
</rss>

