<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decrypted flag under Monitor Logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decrypted-flag-under-monitor-logs/m-p/458204#M101884</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27715"&gt;@inderjit21&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;In addition to what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; mentioned,&amp;nbsp; if you have any URL category with action "Continue" and "Override", basically URL that firewall will send response page. Check this link - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFKCA0" target="_self"&gt;How to Serve a URL Response Page Over an HTTPS Session Without SSL Decryption&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in those cases I think firewall will only decrypt initial request, just to be able to inject the HTTP Redirect, after that I assume nothing is actually decrypted.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jan 2022 08:13:35 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2022-01-12T08:13:35Z</dc:date>
    <item>
      <title>Decrypted flag under Monitor Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypted-flag-under-monitor-logs/m-p/458095#M101880</link>
      <description>&lt;P&gt;Is it normal to see Decrypted flag as yes even when there is no decryption policy configured.&lt;/P&gt;&lt;P&gt;So what traffic will PA decrypt even when there is no decrypt policy?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 22:55:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypted-flag-under-monitor-logs/m-p/458095#M101880</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2022-01-11T22:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypted flag under Monitor Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypted-flag-under-monitor-logs/m-p/458154#M101881</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27715"&gt;@inderjit21&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;GlobalProtect traffic will show decrypted regardless of whether or not you have a decryption policy setup for it. Other than that I can't think of anything off hand that should have that flag without a decryption entry.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 03:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypted-flag-under-monitor-logs/m-p/458154#M101881</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-01-12T03:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypted flag under Monitor Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypted-flag-under-monitor-logs/m-p/458204#M101884</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27715"&gt;@inderjit21&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;In addition to what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; mentioned,&amp;nbsp; if you have any URL category with action "Continue" and "Override", basically URL that firewall will send response page. Check this link - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFKCA0" target="_self"&gt;How to Serve a URL Response Page Over an HTTPS Session Without SSL Decryption&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in those cases I think firewall will only decrypt initial request, just to be able to inject the HTTP Redirect, after that I assume nothing is actually decrypted.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 08:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypted-flag-under-monitor-logs/m-p/458204#M101884</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-01-12T08:13:35Z</dc:date>
    </item>
  </channel>
</rss>

