<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decryption Exclusion methods in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-exclusion-methods/m-p/461459#M102170</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/173922"&gt;@thompso104&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I guess it really depends on how often you are updating the exclusion list and how fast you need that list to populate. An EDL is faster to update and is going to work fine in the majority of cases, but you better have a redundant system to service that EDL behind a load balancer to keep everything working. You wouldn't want the system servicing this list to go down and remove all of the exceptions you have created.&lt;/P&gt;
&lt;P&gt;I generally have both a permanent exception list configured as custom URL categories, and then an EDL configured for temporary exclusions for each organizational group. This way the permanent exclusions are directly linked in the configuration itself and I don't have to worry about the EDL servicer going down and the cache clearing, but I can still quickly add an exception when one is needed. The EDL clears each entry after 48 hours, while the custom URL listings are all considered a permanent or long-term exception.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No one way is really the "correct" way and they all have some considerations to take into account. Generally though my EDL lists are actually dynamic entries that won't stick around long-term, but temporary things. That doesn't mean that anyone using an EDL for all of their decryption exclusions are wrong, it's just not how I've decided to do things. Either method works without issue, the EDL method just has some additional considerations you have to account for.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jan 2022 15:58:53 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-01-27T15:58:53Z</dc:date>
    <item>
      <title>Decryption Exclusion methods</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-exclusion-methods/m-p/461419#M102166</link>
      <description>&lt;P&gt;From what I can tell there are three methods to exclude traffic from decryption:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Custom URL Category - Requires a Commit to the device group when adding URLs&lt;/P&gt;&lt;P&gt;2) SSL Decryption Exclusion List - Must be added to each Firewall template and then Commit&lt;/P&gt;&lt;P&gt;3) External Device List - edit text file on external server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems to me that the EDL is the best/easiest way to quickly exclude URLs as it can be done on the fly and without a Commit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please correct me if I'm missing something and also looking for how other folks are doing this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 14:28:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-exclusion-methods/m-p/461419#M102166</guid>
      <dc:creator>thompso104</dc:creator>
      <dc:date>2022-01-27T14:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption Exclusion methods</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-exclusion-methods/m-p/461459#M102170</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/173922"&gt;@thompso104&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I guess it really depends on how often you are updating the exclusion list and how fast you need that list to populate. An EDL is faster to update and is going to work fine in the majority of cases, but you better have a redundant system to service that EDL behind a load balancer to keep everything working. You wouldn't want the system servicing this list to go down and remove all of the exceptions you have created.&lt;/P&gt;
&lt;P&gt;I generally have both a permanent exception list configured as custom URL categories, and then an EDL configured for temporary exclusions for each organizational group. This way the permanent exclusions are directly linked in the configuration itself and I don't have to worry about the EDL servicer going down and the cache clearing, but I can still quickly add an exception when one is needed. The EDL clears each entry after 48 hours, while the custom URL listings are all considered a permanent or long-term exception.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No one way is really the "correct" way and they all have some considerations to take into account. Generally though my EDL lists are actually dynamic entries that won't stick around long-term, but temporary things. That doesn't mean that anyone using an EDL for all of their decryption exclusions are wrong, it's just not how I've decided to do things. Either method works without issue, the EDL method just has some additional considerations you have to account for.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 15:58:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-exclusion-methods/m-p/461459#M102170</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-01-27T15:58:53Z</dc:date>
    </item>
  </channel>
</rss>

