<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Temporarily disable SSL decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/temporarily-disable-ssl-decryption/m-p/589515#M117485</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firstly sorry for the delay in responding, I did say I would check the existing session theory, I did clear the sessions and it worked as expected, however the browser still held the Firewall cert until cache was cleared, if that makes sense.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jun 2024 09:56:21 GMT</pubDate>
    <dc:creator>laurence64</dc:creator>
    <dc:date>2024-06-13T09:56:21Z</dc:date>
    <item>
      <title>Temporarily disable SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/temporarily-disable-ssl-decryption/m-p/586485#M117041</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was wondering if anybody knew if the temporary disable SSL decryption is actually broken or it is my firewall, I needed to switch it off as I was having issues getting to sso.paloaltonetworks.com (which oddly is not covered by exclusion list) and found that even after running the command set system setting ssl-decrypt skip-ssl-decrypt yes, the traffic was still decrypted, I had to disable the rules and commit to stop the firewall from decrypting, I was hoping to avoid this as it is a PA-220 and takes an age to commit configs, if anybody has any ideas please let me know, I am currently running 10.1.12&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 10:48:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/temporarily-disable-ssl-decryption/m-p/586485#M117041</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2024-05-13T10:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Temporarily disable SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/temporarily-disable-ssl-decryption/m-p/586553#M117062</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163815"&gt;@laurence64&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The "&lt;SPAN&gt;set system setting ssl-decrypt skip-ssl-decrypt yes" should work for you. Is it possible that the traffic post entering the command had an existing session prior to command?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 04:59:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/temporarily-disable-ssl-decryption/m-p/586553#M117062</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-05-14T04:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Temporarily disable SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/temporarily-disable-ssl-decryption/m-p/586625#M117074</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is a good point, so I cleared the CACHE on the browser as the cert can sometimes get stuck there and in the end used a private browser but still decrypted, it was only when I disabled the decryption rule that the traffic was no longer decrypted, but to be fair I did not clear the sessions on the firewall, I will give this a try later today as an experiment, as far as I am aware there are no issues with the command so you are right it should work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for replying so quickly!&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 09:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/temporarily-disable-ssl-decryption/m-p/586625#M117074</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2024-05-14T09:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Temporarily disable SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/temporarily-disable-ssl-decryption/m-p/589515#M117485</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firstly sorry for the delay in responding, I did say I would check the existing session theory, I did clear the sessions and it worked as expected, however the browser still held the Firewall cert until cache was cleared, if that makes sense.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 09:56:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/temporarily-disable-ssl-decryption/m-p/589515#M117485</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2024-06-13T09:56:21Z</dc:date>
    </item>
  </channel>
</rss>

