<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Solution for &amp;quot;SSL decryption bypass for Anydesk&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583076#M116571</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/332852"&gt;@ArtursOstapenko&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see my comments from this post:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/anydesk-issue/td-p/198761" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/anydesk-issue/td-p/198761&lt;/A&gt;&amp;nbsp;(on second page - it's step 3 Custom URL list)&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2024 16:53:22 GMT</pubDate>
    <dc:creator>CosminM</dc:creator>
    <dc:date>2024-04-09T16:53:22Z</dc:date>
    <item>
      <title>Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/385369#M90138</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am being asked a lot about why is Anydesk getting a "decrypt-error" end reason when SSL Decryption is active.&lt;/P&gt;&lt;P&gt;Here is a simple explanation and how to overcome this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you usually going to do with this kind of errors is creating a Decryption bypass rule for Anydesk (in this example)&lt;/P&gt;&lt;P&gt;Since is it impossible to bypass based on application, you would probably use a Custom URL category with a wildcard (*.anydesk.com), and apply it in a bypass rule. Unfortunately, this doesn't work (I'm not sure why, I think Anydesk uses IP addresses and not URLs)&lt;/P&gt;&lt;P&gt;The other option I came across is using an FQND (relays.net.anydesk.com) published in one of the related articles, that also didn't work for me. It was not consistent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I found that Anydesk is being bypassed by default in PANOS (Device --&amp;gt;&amp;nbsp; Certificate management --&amp;gt; SSL Decryption Exclusion).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then why isn't it being bypassed?!&lt;/P&gt;&lt;P&gt;Well, it is because of the certificate Anydesk uses. It is using a Self-Signed certificate, and your device does not trust it (yet).&lt;/P&gt;&lt;P&gt;This is the reason for the decrypt-error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically, what you would like to do now is:&lt;/P&gt;&lt;P&gt;Start a packet capture and export the CA certificate.&lt;/P&gt;&lt;P&gt;Then, import the certificate to your device, and mark it as a trusted CA.&lt;/P&gt;&lt;P&gt;Commit, and now Anydesk should work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am sharing here the CA certificate currently being used by Anydesk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Copy the text below to a text file and rename it to ".crt"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;MIIFYzCCA0ugAwIBAgIJAIf7DQy3sYvoMA0GCSqGSIb3DQEBBQUAMEgxFzAVBgNV&lt;BR /&gt;BAMMDkFueU5ldCBSb290IENBMSAwHgYDVQQKDBdwaGlsYW5kcm8gU29mdHdhcmUg&lt;BR /&gt;R21iSDELMAkGA1UEBhMCREUwHhcNMTQwNDExMDIzNzU1WhcNMjQwNDA4MDIzNzU1&lt;BR /&gt;WjBIMRcwFQYDVQQDDA5BbnlOZXQgUm9vdCBDQTEgMB4GA1UECgwXcGhpbGFuZHJv&lt;BR /&gt;IFNvZnR3YXJlIEdtYkgxCzAJBgNVBAYTAkRFMIICIjANBgkqhkiG9w0BAQEFAAOC&lt;BR /&gt;Ag8AMIICCgKCAgEAtBVBDdoa01og/vnfvwqM8aSt79RUlufigrcNAOrxN+LXjKEW&lt;BR /&gt;O6BoCDiqbdsmvqZpkzaojh5w3KyBHuLdFoM0tRVw9YrNne5dgHxaeKIHpK7m+NYx&lt;BR /&gt;+lx7u+Ba61Evl7/2+zMnkLPY5ODNaDtqh2ymDefYvWHfVmsq4Rwr9Z+/hd2MWwYe&lt;BR /&gt;cX+6SqZAsHcX6iw/W5QUhS6tEWGriPYBu7NHa+KBGPGOOebYewxjhoOscIR1Jy01&lt;BR /&gt;PXt7qM6ySHkIOC2CJn6TSzJ2ZoWn/crxCi/HYg9qQP4aa1gcU+RjwXWDmqt4BEmD&lt;BR /&gt;H+cjcJ+jv2jRMy9M3l6GmH1hfQE09Zzpy0FrrlArZ9XZ8gL8X6NSNLncZ+/6c8WU&lt;BR /&gt;QOq1iveY7Oibu4ZsbzY3ioCMn4T2ykp2InKNUn2FdU1V762v8+UWIwBb6Lbtfp8u&lt;BR /&gt;gEvu1V/cZemJ3NumQwS7zv2pTC8ZM6rmcSCG/kWLl+bIHU9wusfAw/Om8trCpBvd&lt;BR /&gt;iU7sHNp7JI+qQvkUMoNoY8gmvOwTsw0L4rYIxsYGfqMWbxXSGxZSPB8ikSUXFcxC&lt;BR /&gt;gto7qDnHKlDK2UygjJUzdQNwuN+gybKyixs4g3kywxLaM5ZC9JERqsYmMbzqQ4ow&lt;BR /&gt;VGXFQ55QO/qRkw6dOyNKPUPBxiKbaK8v/AGAUhgFIg69auQuydbsxY/zE7MCAwEA&lt;BR /&gt;AaNQME4wHQYDVR0OBBYEFBlleQaAxt6yqliZV7I2XO0BYo1HMB8GA1UdIwQYMBaA&lt;BR /&gt;FBlleQaAxt6yqliZV7I2XO0BYo1HMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEF&lt;BR /&gt;BQADggIBALOqRxekr9JgNBWtJdWOKF7BqrGNMFabR3by4CBUBj3xI8Lvu6Hyn+Or&lt;BR /&gt;DAa/VF4MGjVWbeGTS8WZX5CGflKDlKCgRzby/PLCTXDJyW40XKcPBP3rFl6KvoY7&lt;BR /&gt;oAxzf6P1Xz0rxUEMZwrjSCvKYvapmh7J5ES8F/nbXEWYCWnsyGPvhSlOce35maxJ&lt;BR /&gt;IIqQvFmO8fOlmZkS46d75Wg0q1NarfFEyrp/wqZzkhDqjLHGydXkXisPHkqT+W1M&lt;BR /&gt;BoWQZVHTicwuomu15PDqNzWpfcDLhxIycpMhUYEdowzKlviB9JKgr/cZJPPmzeoR&lt;BR /&gt;KcnxKR2yKxgatKPAWMRwOXiniNd0MsKAYoNY47Q+JbhWLGB3UiWqYTLRl413JDQk&lt;BR /&gt;xdvy3WHI7WNXDsJw5R9S3WxvOLLa7Z2nL4f6s3DlZE35wwLVRtofy/BYIPxElvDK&lt;BR /&gt;tps55s8n0CyZdNTK3keI7d/3nDusimLSdZDZAIHT+MJHjpq9h23O5Zp/KHakd8Y/&lt;BR /&gt;ub9N8cvfDyxz/rRg4yZeg/KuNlaU6aedoT3KXW49Xahv8qWP855ohSfs6WeFNBYN&lt;BR /&gt;RTQUjgcMeyVRVPM/oSrvmheeUd4WZPvd4ciUCYw5u3dz1Ga7SStc+itXi2at96hw&lt;BR /&gt;O4+eCXHeEi7tAhBM1Wcecv86PjRtkmA9RF70IWDubC46cxrDJmr0&lt;BR /&gt;-----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this is helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 08:45:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/385369#M90138</guid>
      <dc:creator>OZamir</dc:creator>
      <dc:date>2021-03-22T08:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/392550#M90916</link>
      <description>&lt;P&gt;And idea is If you want you can remove Anydesk from the "SSL Decryption Exclusion" and test decrypting it and presenting the users with the trusted certificate as a workaround (they will not see the self signed cert in this way) just check also if the SSL decryption profile allows self signed certficates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPJfCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPJfCAO&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Mar 2021 22:23:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/392550#M90916</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-21T22:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/392607#M90927</link>
      <description>&lt;P&gt;Due to client Certificate authentication, you cannot decrypt Anydesk.&lt;/P&gt;&lt;P&gt;This is Why is it added by PANW to "SSL Decryption exclusion" list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The need to import the certificate into the NGFW is to make PANOS trust the self-signed certificate used by Anydesk server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 08:51:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/392607#M90927</guid>
      <dc:creator>OZamir</dc:creator>
      <dc:date>2021-03-22T08:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/392744#M90947</link>
      <description>&lt;P&gt;In this cas you are right that Palo Alto can't decrypt it.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 16:47:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/392744#M90947</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-22T16:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/430695#M95026</link>
      <description>&lt;P&gt;It need even this anydesk relay certificate. After seen works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;MIIFYzCCA0ugAwIBAgIJAIf7DQy3sYvoMA0GCSqGSIb3DQEBBQUAMEgxFzAVBgNV&lt;BR /&gt;BAMMDkFueU5ldCBSb290IENBMSAwHgYDVQQKDBdwaGlsYW5kcm8gU29mdHdhcmUg&lt;BR /&gt;R21iSDELMAkGA1UEBhMCREUwHhcNMTQwNDExMDIzNzU1WhcNMjQwNDA4MDIzNzU1&lt;BR /&gt;WjBIMRcwFQYDVQQDDA5BbnlOZXQgUm9vdCBDQTEgMB4GA1UECgwXcGhpbGFuZHJv&lt;BR /&gt;IFNvZnR3YXJlIEdtYkgxCzAJBgNVBAYTAkRFMIICIjANBgkqhkiG9w0BAQEFAAOC&lt;BR /&gt;Ag8AMIICCgKCAgEAtBVBDdoa01og/vnfvwqM8aSt79RUlufigrcNAOrxN+LXjKEW&lt;BR /&gt;O6BoCDiqbdsmvqZpkzaojh5w3KyBHuLdFoM0tRVw9YrNne5dgHxaeKIHpK7m+NYx&lt;BR /&gt;+lx7u+Ba61Evl7/2+zMnkLPY5ODNaDtqh2ymDefYvWHfVmsq4Rwr9Z+/hd2MWwYe&lt;BR /&gt;cX+6SqZAsHcX6iw/W5QUhS6tEWGriPYBu7NHa+KBGPGOOebYewxjhoOscIR1Jy01&lt;BR /&gt;PXt7qM6ySHkIOC2CJn6TSzJ2ZoWn/crxCi/HYg9qQP4aa1gcU+RjwXWDmqt4BEmD&lt;BR /&gt;H+cjcJ+jv2jRMy9M3l6GmH1hfQE09Zzpy0FrrlArZ9XZ8gL8X6NSNLncZ+/6c8WU&lt;BR /&gt;QOq1iveY7Oibu4ZsbzY3ioCMn4T2ykp2InKNUn2FdU1V762v8+UWIwBb6Lbtfp8u&lt;BR /&gt;gEvu1V/cZemJ3NumQwS7zv2pTC8ZM6rmcSCG/kWLl+bIHU9wusfAw/Om8trCpBvd&lt;BR /&gt;iU7sHNp7JI+qQvkUMoNoY8gmvOwTsw0L4rYIxsYGfqMWbxXSGxZSPB8ikSUXFcxC&lt;BR /&gt;gto7qDnHKlDK2UygjJUzdQNwuN+gybKyixs4g3kywxLaM5ZC9JERqsYmMbzqQ4ow&lt;BR /&gt;VGXFQ55QO/qRkw6dOyNKPUPBxiKbaK8v/AGAUhgFIg69auQuydbsxY/zE7MCAwEA&lt;BR /&gt;AaNQME4wHQYDVR0OBBYEFBlleQaAxt6yqliZV7I2XO0BYo1HMB8GA1UdIwQYMBaA&lt;BR /&gt;FBlleQaAxt6yqliZV7I2XO0BYo1HMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEF&lt;BR /&gt;BQADggIBALOqRxekr9JgNBWtJdWOKF7BqrGNMFabR3by4CBUBj3xI8Lvu6Hyn+Or&lt;BR /&gt;DAa/VF4MGjVWbeGTS8WZX5CGflKDlKCgRzby/PLCTXDJyW40XKcPBP3rFl6KvoY7&lt;BR /&gt;oAxzf6P1Xz0rxUEMZwrjSCvKYvapmh7J5ES8F/nbXEWYCWnsyGPvhSlOce35maxJ&lt;BR /&gt;IIqQvFmO8fOlmZkS46d75Wg0q1NarfFEyrp/wqZzkhDqjLHGydXkXisPHkqT+W1M&lt;BR /&gt;BoWQZVHTicwuomu15PDqNzWpfcDLhxIycpMhUYEdowzKlviB9JKgr/cZJPPmzeoR&lt;BR /&gt;KcnxKR2yKxgatKPAWMRwOXiniNd0MsKAYoNY47Q+JbhWLGB3UiWqYTLRl413JDQk&lt;BR /&gt;xdvy3WHI7WNXDsJw5R9S3WxvOLLa7Z2nL4f6s3DlZE35wwLVRtofy/BYIPxElvDK&lt;BR /&gt;tps55s8n0CyZdNTK3keI7d/3nDusimLSdZDZAIHT+MJHjpq9h23O5Zp/KHakd8Y/&lt;BR /&gt;ub9N8cvfDyxz/rRg4yZeg/KuNlaU6aedoT3KXW49Xahv8qWP855ohSfs6WeFNBYN&lt;BR /&gt;RTQUjgcMeyVRVPM/oSrvmheeUd4WZPvd4ciUCYw5u3dz1Ga7SStc+itXi2at96hw&lt;BR /&gt;O4+eCXHeEi7tAhBM1Wcecv86PjRtkmA9RF70IWDubC46cxrDJmr0&lt;BR /&gt;-----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Claudio Verniani - PAE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 07:43:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/430695#M95026</guid>
      <dc:creator>cverniani</dc:creator>
      <dc:date>2021-09-01T07:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/580827#M116296</link>
      <description>&lt;P&gt;Does anyone have the updated CA certificate? This one expires April 7th this year.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 19:58:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/580827#M116296</guid>
      <dc:creator>hilgart</dc:creator>
      <dc:date>2024-03-18T19:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/581554#M116392</link>
      <description>&lt;P&gt;I am in the same boat.&amp;nbsp; I cannot find a replacement anywhere.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 15:33:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/581554#M116392</guid>
      <dc:creator>jfrost</dc:creator>
      <dc:date>2024-03-25T15:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/582786#M116524</link>
      <description>&lt;P&gt;Same for me - anybody has the new certificate?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 10:51:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/582786#M116524</guid>
      <dc:creator>MatwoksNetTeam</dc:creator>
      <dc:date>2024-04-05T10:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/582789#M116525</link>
      <description>&lt;P&gt;Have you fixed it somehow?&lt;/P&gt;
&lt;P&gt;We got same problem, can't get new CA certificate from sslabs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Managed to get *.relay.net.anydesk.com certificate, but it's not working without AnyNet Root CA 2&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 11:19:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/582789#M116525</guid>
      <dc:creator>ArtursOstapenko</dc:creator>
      <dc:date>2024-04-05T11:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/582949#M116542</link>
      <description>&lt;P&gt;I was trying to download it using openssl but only managed to get Relay one &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 15:24:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/582949#M116542</guid>
      <dc:creator>Tomasz_W</dc:creator>
      <dc:date>2024-04-08T15:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/582961#M116545</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In the past it was working the workaround from this discussion:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/anydesk-issue/m-p/516607#M107283" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/anydesk-issue/m-p/516607#M107283&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Now, when I can't have the&amp;nbsp;AnyNet Root CA 2, I modified my Decryption Profile and unchecked "Block session with untrusted issuers" and I'm based only on URL's&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Untitled.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58886i1B070FAD822122F4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe this information will help you.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 19:16:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/582961#M116545</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2024-04-08T19:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/582998#M116554</link>
      <description>&lt;P&gt;In my case both options unchecked, but still not working, can yo share your Decryption policy for AnyDesk?&amp;nbsp;&lt;BR /&gt;I'm using URL category *.net.anydesk.com and action no-decrypt.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArtursOstapenko_0-1712641952378.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58895i3106CF6B74DF8359/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ArtursOstapenko_0-1712641952378.png" alt="ArtursOstapenko_0-1712641952378.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 05:53:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/582998#M116554</guid>
      <dc:creator>ArtursOstapenko</dc:creator>
      <dc:date>2024-04-09T05:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583035#M116562</link>
      <description>&lt;P&gt;this has stopped working once the anynet rootCA cert expired on the 7th of april , we urgently need the updated ROOT CA cert.&lt;/P&gt;
&lt;P&gt;please someone post it.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 12:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583035#M116562</guid>
      <dc:creator>S.Support212931</dc:creator>
      <dc:date>2024-04-09T12:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583038#M116564</link>
      <description>&lt;P&gt;Welcome to the club .&amp;nbsp; (&amp;nbsp;By the way anydesk started using the new certificate on 4/April/24 )&amp;nbsp;&lt;BR /&gt;We have 2 open tickets with anydeks and 1 with PaloAlto and still nobody is helping in any way.&amp;nbsp;&lt;BR /&gt;If someone manage to find the new certificate from the captures please share.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 12:45:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583038#M116564</guid>
      <dc:creator>MatwoksNetTeam</dc:creator>
      <dc:date>2024-04-09T12:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583076#M116571</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/332852"&gt;@ArtursOstapenko&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see my comments from this post:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/anydesk-issue/td-p/198761" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/anydesk-issue/td-p/198761&lt;/A&gt;&amp;nbsp;(on second page - it's step 3 Custom URL list)&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 16:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583076#M116571</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2024-04-09T16:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583086#M116573</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;It works without certificate. Solution by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197789"&gt;@CosminM&lt;/a&gt; with a twist:&lt;/P&gt;
&lt;P&gt;So, create URL list with those:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;anynet%20relay/&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;anynet%20relay:80/&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;anynet%20relay:6568/&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;anynet relay:6568/&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;anynet relay:80/&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;anynet relay/&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Decryption profile like that:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tomasz_W_0-1712685065329.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58905i1399705F6ADD7D07/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Tomasz_W_0-1712685065329.png" alt="Tomasz_W_0-1712685065329.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And Decryption rule like that:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tomasz_W_1-1712685142874.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58906i15AA0ACAD81E1C98/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Tomasz_W_1-1712685142874.png" alt="Tomasz_W_1-1712685142874.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And this is how it looks in logs:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tomasz_W_2-1712685484091.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58907i0CCB1EFA04F5BE7D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Tomasz_W_2-1712685484091.png" alt="Tomasz_W_2-1712685484091.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 17:58:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583086#M116573</guid>
      <dc:creator>Tomasz_W</dc:creator>
      <dc:date>2024-04-09T17:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583088#M116574</link>
      <description>&lt;P&gt;so we have to create a service port for that decryption rule ? ( see my pic )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 18:14:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583088#M116574</guid>
      <dc:creator>S.Support212931</dc:creator>
      <dc:date>2024-04-09T18:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583157#M116580</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1249999795"&gt;@S.Support212931&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;One of the steps it's to create a service for TCP &lt;STRONG&gt;destination port 6568&lt;/STRONG&gt;. The &lt;STRONG&gt;source port&lt;/STRONG&gt; it's dynamic and in your service should be empty.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="AnyDesk-Service.png" style="width: 870px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58941iE28FB4D51A9064A6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="AnyDesk-Service.png" alt="AnyDesk-Service.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 03:47:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583157#M116580</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2024-04-10T03:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583187#M116582</link>
      <description>&lt;P&gt;I see 2 issues with this&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;1. This solution doesn't just allow anydesk to bypass the decryption&amp;nbsp; -&amp;nbsp; it basically allows everything to bypass the decryption for destination port 80 and 6568.&amp;nbsp;How to you make sure only anydesk is allowed in this case ?&lt;BR /&gt;&lt;BR /&gt;2. Even if we find a way to make it only for anydesk - it then bypass the decryption which is not something we want.&amp;nbsp;&lt;BR /&gt;What is someone transfers a malicious file through anydesk during the session - How will the firewall be able to see it if decryption is off.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 06:20:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583187#M116582</guid>
      <dc:creator>MatwoksNetTeam</dc:creator>
      <dc:date>2024-04-10T06:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Solution for "SSL decryption bypass for Anydesk"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583192#M116583</link>
      <description>&lt;P&gt;This is reply what I've got from AnyDesk support:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&lt;SPAN data-ogsb="rgb(255, 255, 255)"&gt;AnyDesk does not use the PKI (public key infrastructure). Instead, we use our own trust chain to validate the server certificates. This gives us more control over the process and the certificate validation. For example, you can not just install a certificate as a trusted root certificate on the computer and use it to man-in-the-middle the connection.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&lt;SPAN data-ogsb="rgb(255, 255, 255)"&gt;Usually, you need to check the common name, so that someone can not use a certificate that was rightfully generated for domain&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ogsb="rgb(255, 255, 255)"&gt;&lt;A href="http://a.com/" data-auth="NotApplicable" data-linkindex="0" data-ogsc="" target="_blank"&gt;a.com&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ogsb="rgb(255, 255, 255)"&gt;for another domain&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ogsb="rgb(255, 255, 255)"&gt;&lt;A href="http://b.com/" data-auth="NotApplicable" data-linkindex="1" data-ogsc="" target="_blank"&gt;b.com&lt;/A&gt;, that he does not have access to. We do not generate certificates for other people or purposes, so in our case, it is enough to know that the certificate was signed by our CA.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&lt;SPAN data-ogsb="rgb(255, 255, 255)"&gt;This error happens because the system checking the certificate does not trust our root CA. The AnyDesk client however will.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN data-ogsb="rgb(255, 255, 255)"&gt;There is no issue with the certificate being self-signed because the client generates the certificate by itself on the first start and it will only be linked to a new AnyDesk client ID on the server.&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 10 Apr 2024 06:46:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/solution-for-quot-ssl-decryption-bypass-for-anydesk-quot/m-p/583192#M116583</guid>
      <dc:creator>ArtursOstapenko</dc:creator>
      <dc:date>2024-04-10T06:46:52Z</dc:date>
    </item>
  </channel>
</rss>

