<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dectyption Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dectyption-issue/m-p/546585#M111707</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Also some websites do not like it when you decrypt them. I know a lot of the Microsoft sites are like this and its best to bypass decryption on them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jun 2023 21:31:24 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2023-06-20T21:31:24Z</dc:date>
    <item>
      <title>Dectyption Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dectyption-issue/m-p/546352#M111671</link>
      <description>&lt;P&gt;Dear Team!&lt;/P&gt;
&lt;P&gt;I got a problem with Decryption on some websites. For example admin.microsoft.com. When I try to open this website, the web browser gives me a simple white blank without any content in it. In this case, decryption is on. I saw the error, depending on the certificate chain of trust, and I follow the documentation and imported the missing certificate to Firewall and then to the end user machine, but, not fixed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This issue was in 10.1.7 and continues in 10.1.9 h2 I think. And, this problem the first time was faced while upgrading to 10.1.7.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 06:05:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dectyption-issue/m-p/546352#M111671</guid>
      <dc:creator>RovshanRajabli</dc:creator>
      <dc:date>2023-06-19T06:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dectyption Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dectyption-issue/m-p/546472#M111699</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227026"&gt;@RovshanRajabli&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might be running into &lt;SPAN&gt;bug behavior. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I've seen this exact same behaviour when &lt;/SPAN&gt;&lt;SPAN&gt;http2 decrypted traffic was getting identified as unknown-tcp.&amp;nbsp; Please check if that's the case or if it is being identified correctly.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The root cause in my example was that each large http2 header holds a swbuf 4 until the end of the flow. This causes the swbuf 4 depletion.&amp;nbsp; You can check this with the following command as well:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@Lab&amp;gt; debug dataplane pool statistics | match "buffer 4"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As a workaround you could try to strip ALPN for the website that causes the buffer depletion.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That being said, I recommend grabbing a tech support file and have it analyzed by support in order to confirm if you are hitting this exact same bug or if you are experiencing a different issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 11:27:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dectyption-issue/m-p/546472#M111699</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-06-20T11:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Dectyption Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dectyption-issue/m-p/546585#M111707</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Also some websites do not like it when you decrypt them. I know a lot of the Microsoft sites are like this and its best to bypass decryption on them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 21:31:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dectyption-issue/m-p/546585#M111707</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-06-20T21:31:24Z</dc:date>
    </item>
  </channel>
</rss>

