<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No anti-virus response page for SSL in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14549#M10679</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what version of PANOS are you running on the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and what version of the app/threat content?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Mar 2011 16:15:19 GMT</pubDate>
    <dc:creator>bpappas</dc:creator>
    <dc:date>2011-03-16T16:15:19Z</dc:date>
    <item>
      <title>No anti-virus response page for SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14546#M10676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have SSL decryption setup and working.&amp;nbsp; When I go to eicar.org, the http test returns my response page.&amp;nbsp; The https test doesn't return any response page; although I can see in the threat log that it was properly denied.&amp;nbsp; The browser just spins waiting for something to return.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've attached a snippet from the log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Todd&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 10:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14546#M10676</guid>
      <dc:creator>tcjnole64</dc:creator>
      <dc:date>2011-03-16T10:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: No anti-virus response page for SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14547#M10677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Todd,&amp;nbsp; actually https traffic should show up as Application ssl and not web-browsing. In your security policy did you allow application ssl for this test ?&amp;nbsp; rgds Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 15:35:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14547#M10677</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2011-03-16T15:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: No anti-virus response page for SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14548#M10678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interestingly, with decryption off it shows port 443, appl ssl.&amp;nbsp; With it on, it shows port 443, appl web-browsing.&amp;nbsp; It's doing the right thing as far as blocking the test virus.&amp;nbsp; I'm just not getting the anti-virus response page.&amp;nbsp; The browser is waiting...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 15:45:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14548#M10678</guid>
      <dc:creator>tcjnole64</dc:creator>
      <dc:date>2011-03-16T15:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: No anti-virus response page for SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14549#M10679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what version of PANOS are you running on the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and what version of the app/threat content?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 16:15:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14549#M10679</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-03-16T16:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: No anti-virus response page for SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14550#M10680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, we have the same problem, the browser just shows "can not display page". Our PA-500 is running on 3.1.8 with&amp;nbsp; Version 241-941 for apps and threats.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Apr 2011 09:14:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14550#M10680</guid>
      <dc:creator>sboelter</dc:creator>
      <dc:date>2011-04-20T09:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: No anti-virus response page for SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14551#M10681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@tcjnole64:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when SSL decryption is ON the firewall will see the decrypted application (in this case web-browsing). So if you are using SSL decryption then your policy needs to allow SSL and web-browsing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;question: are you using a self-signed certificate for the response pages? we have observed, in some cases, that the browser times out while attempting to look up the certificate when using self-signed certificates. we have had some luck placing self-signed certificates in the browser's "trusted root certificate" store instead of the default "trusted personal certificate" store.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Apr 2011 14:03:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/14551#M10681</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-04-20T14:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: No anti-virus response page for SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/267534#M74474</link>
      <description>&lt;P&gt;Has there been any update on this, that someone from PANW could respond back with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have decryption enabled, with a self-signed cert in my trusted cert authority stores.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The response page is properly seen with web-browsing, port 80, threat log show reset-server as action.&lt;/P&gt;&lt;P&gt;The response pages is NOT seen with (decryption enabled) with web-browsing, port 443. Threat log shows reset-both as action.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I changed the AV profile to perform reset-server, and tested with decryption, and still same issue (Chrome, FireFox, IE)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a very brief article at&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMeCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMeCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;CAN I ISSUE BLOCK PAGES OVER SSL?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#333399"&gt;&amp;nbsp;Created On&amp;nbsp;02/07/19 23:52 PM - Last Updated&amp;nbsp;02/07/19 23:52 PM&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;Resolution&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;Yes.&amp;nbsp; For URL filtering, file blocking, and antivirus profiles, you can automatically issue a block page by setting the policy action to "block".&amp;nbsp; &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#333399"&gt;In order to issue a block page over SSL, you must also enable SSL decrypt.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This above article talks about a policy action of block. Policy...not security profile (which there is no block in AV...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a rule in 9.0.2 software.&lt;/P&gt;&lt;P&gt;Trusted --&amp;gt; Untrusted--&amp;gt;Any--&amp;gt; Application-default (allowed) with an AV security profile that shows http (action default or reset-both)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I browse to Eicar (on port 80) download the Eicar test file.&amp;nbsp; I am blocked.&lt;/P&gt;&lt;P&gt;When I do this with Decryption enabled, now we have web-browsing on 443 (in 9.0.2, app-default include secured/unsecured ports in the app signature, with a "Page Cannot be Displayed"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What steps am I missing.&amp;nbsp; What explanation do I give to my students/customers who ask why this is not working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steve&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 19:22:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/267534#M74474</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-06-06T19:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: No anti-virus response page for SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/267541#M74475</link>
      <description>&lt;P&gt;Well, rather than remove my post... I found this one which I think explains a little better.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZJCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="fieldLabel"&gt;Resolution&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Symptom&lt;/P&gt;&lt;P&gt;When using SSL decryption policy to block malware, the block page does not always display.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cause&lt;/P&gt;&lt;P&gt;When requesting a web page, browsers tend to allow any response with a header similar to this:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Accept: text/html, image/png, */*;q=0.1\r\n&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The */* indicates any response will be accepted.&lt;/P&gt;&lt;P&gt;When requesting a specific object (.zip, .txt, etc.) the client browser may only allow that type of response, limiting what the browser will display. If requesting a .txt file, you may only see:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Accept: text/text\r\n&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the firewall displays a response page indicating that the request is blocked due to a virus, it displays it as an html page. The mime-type is text/html. This can mean that if the browser is only allowing text/text, the page will not be displayed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During an SSL communication, the client browser may close the request rather than display an error that the mime-type did not match what was requested. This results in the browser just "spinning", not displaying any page until an error is presented after a timeout.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;owner: gwesson&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 19:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/267541#M74475</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-06-06T19:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: No anti-virus response page for SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/267542#M74476</link>
      <description>&lt;P&gt;However, as I continue to understand this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is different between a port 80 browser page in terms of&amp;nbsp;&lt;/P&gt;&lt;P&gt;When requesting a web page, browsers tend to allow any response with a header similar to this:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Accept: text/html, image/png, */*;q=0.1\r\n&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And when the Response Page DOES work on port 80.&lt;/P&gt;&lt;P&gt;Does the same port 80 browset see&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;Accept: text/text\r\n&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why does it not provide same Page Cannot Be Displayed Error?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PANW, please advise.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 19:32:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/267542#M74476</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-06-06T19:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: No anti-virus response page for SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/267555#M74477</link>
      <description>&lt;P&gt;AHA.&amp;nbsp; &amp;nbsp;I found the best response, and it does make sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm6lCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm6lCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Antivirus block page presents inconsistent behavior&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN class="synopsis-grey"&gt;Created On&amp;nbsp;02/07/19 23:36 PM - Last Updated&amp;nbsp;02/07/19 23:36 PM&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="topics"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="fieldLabel"&gt;Symptom&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Testing a virus download from different websites using SSL Decryption yields different results.&lt;/P&gt;&lt;P&gt;Sometimes you receive a response page indicating Virus/Spyware Download block, and on other sites you don't see a response page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Examples shown are 2 websites with the Eicar test file.&lt;/P&gt;&lt;P&gt;One is broken, 2nd one works as expected)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The reason for the behavior presented with the first website,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://secure.eicar.org/eicarcom2.zip" target="_blank" rel="noopener"&gt;https://secure.eicar.org/eicarcom2.zip&lt;/A&gt;&lt;SPAN&gt;, is, we don't detect the threat in the first packet of the response. In this case, the HTTP headers were already transmitted to the client. In this situation we can't send the&amp;nbsp;response page, and therefore the only action taken is sending a reset to both client and server as configured in the profile.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In the case of the second website,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.ikarussecurity.com/fileadmin/user_upload/testviren/eicarcom2.zip" target="_blank" rel="noopener"&gt;https://www.ikarussecurity.com/fileadmin/user_upload/testviren&lt;SPAN&gt;/eicarcom2.zip&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;, we detect the threat early, in the first packet of the response, so we are able to send a&amp;nbsp;response page to the client.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This answer my question and links together 2 very similar knowledge articles, so hopefully someone will "like" my responses.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 19:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-anti-virus-response-page-for-ssl/m-p/267555#M74477</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-06-06T19:38:10Z</dc:date>
    </item>
  </channel>
</rss>

