<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: no decryption policy set, wan to wan traffic decrypt is yes in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527659#M109007</link>
    <description>&lt;P&gt;If ssl session is terminated on wan interface, for example; globalprotect portal, it will be wan2wan session and also decrypted.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 07:50:51 GMT</pubDate>
    <dc:creator>emr_1</dc:creator>
    <dc:date>2023-01-19T07:50:51Z</dc:date>
    <item>
      <title>no decryption policy set, wan to wan traffic decrypt is yes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527658#M109006</link>
      <description>&lt;P&gt;Hi All ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We did not set decryption policy&lt;BR /&gt;But in the threat log, it is seen that decrypt is yes, and the traffic is wan to wan.&lt;/P&gt;
&lt;P&gt;Under what circumstances will the log of wan to wan decrypt is yes be generated?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 07:47:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527658#M109006</guid>
      <dc:creator>Hsinyu</dc:creator>
      <dc:date>2023-01-19T07:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: no decryption policy set, wan to wan traffic decrypt is yes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527659#M109007</link>
      <description>&lt;P&gt;If ssl session is terminated on wan interface, for example; globalprotect portal, it will be wan2wan session and also decrypted.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 07:50:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527659#M109007</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2023-01-19T07:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: no decryption policy set, wan to wan traffic decrypt is yes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527660#M109008</link>
      <description>&lt;P&gt;Hi Emr&lt;/P&gt;
&lt;P&gt;Want to confirm if my understanding is correct&lt;BR /&gt;As long as the ssl 443 session from wan to wan ends on the wan interface, it will be decrypted by default on the PA. If it is a threat, it will be blocked, right?&lt;/P&gt;
&lt;P&gt;Is there any other possibility besides ssl .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 08:06:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527660#M109008</guid>
      <dc:creator>Hsinyu</dc:creator>
      <dc:date>2023-01-19T08:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: no decryption policy set, wan to wan traffic decrypt is yes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527664#M109009</link>
      <description>&lt;P&gt;yes to first part.&lt;/P&gt;
&lt;P&gt;the action (blocked you said) depends on your configuration. If you configure it to be blocked, you are correct.&lt;BR /&gt;&lt;BR /&gt;If you are pointing this decryption, this indicates ssl decryption was applied to the ssl / tls session&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image 002.png" style="width: 262px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47179i59078BB3875E5667/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Image 002.png" alt="Image 002.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 08:51:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527664#M109009</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2023-01-19T08:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: no decryption policy set, wan to wan traffic decrypt is yes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527747#M109019</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/199542"&gt;@Hsinyu&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Just to be abundantly clear, the only time that traffic is automatically decrypted by the firewall is if the traffic terminates on the firewall. So in the example of a GlobalProtect Portal/Gateway, that traffic will be decrypted automatically without anything being configured by you as the admin.&lt;/P&gt;
&lt;P&gt;In the event that you have a device setup in your WAN/untrust zone outside of the above examples, it won't be automatically decrypted by the firewall unless you setup a decryption policy. For example if I hand a VPN concentrator off of a firewall and just place it in a WAN/untrust zone, the firewall won't automatically start decrypting that traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That might add a bit of confusion as this isn't a common deployment that folks do, but it's important to have that distinction present.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 17:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-decryption-policy-set-wan-to-wan-traffic-decrypt-is-yes/m-p/527747#M109019</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-01-19T17:36:18Z</dc:date>
    </item>
  </channel>
</rss>

