<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filtering Override SSL Certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14504#M10649</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like others said, there is not way to override the SSL used for the override page. I was making a suggestion that Palo Alto Networks make that SSL on the override page optional in a future revision of the PAN OS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Sep 2010 22:17:21 GMT</pubDate>
    <dc:creator>nftechservices</dc:creator>
    <dc:date>2010-09-01T22:17:21Z</dc:date>
    <item>
      <title>URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14497#M10642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've been experimenting with the URL override feature.&amp;nbsp; Works fine, however even with the PANs self-signed certs in the PC's trusted root authorities store, I can't seem to get away from getting a "mismatch" warning because when someone goes to www.overridesite.com the SSL cert is only valid for pan.ourdomain.com even if it trusts the CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this just how it is or is there anything I can do to make it a bit more seamless please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Apr 2010 17:19:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14497#M10642</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-04-29T17:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14498#M10643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is expected behavior and there is no way around it.&amp;nbsp; You can't load a wild card cert that would be accepted by other all other sites.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Apr 2010 00:08:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14498#M10643</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-04-30T00:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14499#M10644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply, are there any plans to change the behaviour?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ask as we educate our users not to click on things if they're not 100% sure what they are etc. and I can imagine this causing a fair bit of confusion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it be put in as a feature request please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Apr 2010 16:14:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14499#M10644</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-04-30T16:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14500#M10645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems like you are trying to put Fort Knox around a nickel. The only part worth protecting on that page is potentially the override password. A better solution would be to make SSL optional on the override page, or make it a 2 step process for a user to override.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Present an unencrypted block page with a button to override.&lt;/P&gt;&lt;P&gt;2. Present an encrypted password request page if the user wishes to override.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would prevent the annoyance and confusion caused by a casual block and then you would only have to deal with the certificate mismatch when you truly wish to override the block.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jun 2010 22:17:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14500#M10645</guid>
      <dc:creator>nftechservices</dc:creator>
      <dc:date>2010-06-08T22:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14501#M10646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I'm concerned the override page doesn't have to be SSL at all, that was the default and I didn't spot an option for it to not be SSL - if that's possible I'm interested to know how?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jun 2010 17:02:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14501#M10646</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-06-09T17:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14502#M10647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, can I use the override page without it using SSL?&amp;nbsp; I don't see anything obvious in the GUI or the manual on how to do so.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Aug 2010 10:48:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14502#M10647</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-08-28T10:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14503#M10648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is not currently a way to use the URL Filtering override feature without using SSL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 22:06:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14503#M10648</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2010-09-01T22:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14504#M10649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like others said, there is not way to override the SSL used for the override page. I was making a suggestion that Palo Alto Networks make that SSL on the override page optional in a future revision of the PAN OS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 22:17:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14504#M10649</guid>
      <dc:creator>nftechservices</dc:creator>
      <dc:date>2010-09-01T22:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14505#M10650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@nftech:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes. you are correct. Since this feature does not exist it would require a feature request which you can request via your Sales Engineer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 22:20:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14505#M10650</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2010-09-01T22:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14506#M10651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doesn't the URL Override redirect feature resolve this issue?&amp;nbsp; If you redirect to an interface IP or a DN that maps to an interface IP on the firewall and ensure that you're presenting an internally valid certificate, then the users shouldn't get any certificate errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just got this working in my test environment a couple of days ago mysefl (running 3.1.4).&amp;nbsp; If I remember correctly, generate the cert 1st in the SSL VPN area of the certificates left hand link on the Device tab.&amp;nbsp; Once a cert has been applied, then go to the Setup left hand link of the Device tab and there should be a URL Override area on that page.&amp;nbsp; If you edit that area, you should be able to configure the specifics of the Override feature, including the Override type (redirect/transparent).&amp;nbsp; Set it to redirect, select the newly created certificate that should be present and then enter the DN that maps to proper IP address of the firewall.&amp;nbsp; Commit and you should be good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when the user tries to access a URL that falls within an override set category, their browser should be redirected via HTTPS to the DN, which should be mapped to the firewall.&amp;nbsp; If the cert is trusted, you should be set - no certificate warnings (assuming your cert was signed by a trusted authority).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tariq&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Sep 2010 09:59:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14506#M10651</guid>
      <dc:creator>rahmant</dc:creator>
      <dc:date>2010-09-11T09:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14507#M10652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you &lt;STRONG&gt;&lt;EM&gt;so &lt;/EM&gt;&lt;/STRONG&gt;much!&amp;nbsp; Our reseller didn't mention this option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesn't work on the management IP only on the LAN NIC, but it does work and suggests all I need to do is go buy a rapidssl or other cheap cert whose root CA is trusted on all our PC's (I know I could push one out but for $10 it's not worth the hassle).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perfect!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(the only slight negative is that it seems I can't use the same cert for both URL admin override and for the management interface cert as I obviously can't have forward DNS internally mapping the FQDN to both the management and internal LAN NIC).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Sep 2010 10:40:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14507#M10652</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-09-11T10:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Override SSL Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14508#M10653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're welcome &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tariq&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Sep 2010 10:51:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-override-ssl-certificate/m-p/14508#M10653</guid>
      <dc:creator>rahmant</dc:creator>
      <dc:date>2010-09-11T10:51:12Z</dc:date>
    </item>
  </channel>
</rss>

