<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL decryption exclusion or decryption policy in Web Proxy Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/web-proxy-discussions/ssl-decryption-exclusion-or-decryption-policy/m-p/1239010#M64</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a host unsuccessfully attempting to connect to AWS. The firewall is resetting the connection, based on packet captures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which would be the best way to exclude this traffic from decryption: the SSL decryption exclusion list or a decryption policy? I tried adding the source host to an existing no-decryption policy, but it still hit the decryption policy, despite the no-decryption rule being above the decryption rule.&lt;/P&gt;
&lt;P&gt;I've also tried excluding the Amazon AWS address by using the SSL decryption exclusion list, but this fails, as well. I suspect, though, I'm not inputting the wildcard and domain correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, what would be the best way to accomplish the goal?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 29 Sep 2025 12:12:43 GMT</pubDate>
    <dc:creator>DamianCleveland</dc:creator>
    <dc:date>2025-09-29T12:12:43Z</dc:date>
    <item>
      <title>SSL decryption exclusion or decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/web-proxy-discussions/ssl-decryption-exclusion-or-decryption-policy/m-p/1239010#M64</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a host unsuccessfully attempting to connect to AWS. The firewall is resetting the connection, based on packet captures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which would be the best way to exclude this traffic from decryption: the SSL decryption exclusion list or a decryption policy? I tried adding the source host to an existing no-decryption policy, but it still hit the decryption policy, despite the no-decryption rule being above the decryption rule.&lt;/P&gt;
&lt;P&gt;I've also tried excluding the Amazon AWS address by using the SSL decryption exclusion list, but this fails, as well. I suspect, though, I'm not inputting the wildcard and domain correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, what would be the best way to accomplish the goal?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 12:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/web-proxy-discussions/ssl-decryption-exclusion-or-decryption-policy/m-p/1239010#M64</guid>
      <dc:creator>DamianCleveland</dc:creator>
      <dc:date>2025-09-29T12:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption exclusion or decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/web-proxy-discussions/ssl-decryption-exclusion-or-decryption-policy/m-p/1245979#M66</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;A id="link_10" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70768" target="_self" aria-label="View Profile of DamianCleveland"&gt;&lt;SPAN class=""&gt;DamianCleveland ,&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Hope you are doing well...&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Try creating AWS EDL (Extenal dynamic list )object depend on the service you trying to access in AWS and add this under URL category of your decryption&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;How to create EDL:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/configure-the-firewall-to-access-an-external-dynamic-list-from-the-edl-hosting-service/create-an-external-dynamic-list-using-the-edl-hosting-service" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/configure-the-firewall-to-access-an-external-dynamic-list-from-the-edl-hosting-service/create-an-external-dynamic-list-using-the-edl-hosting-service&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;AWS EDL Hosting URL list:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/resources/edl-hosting-service?ref=packetswitch.co.uk" target="_blank"&gt;https://docs.paloaltonetworks.com/resources/edl-hosting-service?ref=packetswitch.co.uk&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#666666"&gt;&lt;SPAN&gt;If this info helps marks this as answered ...cheers:)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 07:18:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/web-proxy-discussions/ssl-decryption-exclusion-or-decryption-policy/m-p/1245979#M66</guid>
      <dc:creator>Vijayanand</dc:creator>
      <dc:date>2026-01-20T07:18:18Z</dc:date>
    </item>
  </channel>
</rss>

