<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption Auto Tag URL to No Longer Decrypt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-auto-tag-url-to-no-longer-decrypt/m-p/598153#M118982</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109249"&gt;@Adam_DiMarco&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am surprised no one responded to this post.&amp;nbsp; Here is a video how to do it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=WgG6Hi0T73g" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=WgG6Hi0T73g&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 18 Sep 2024 17:09:17 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-09-18T17:09:17Z</dc:date>
    <item>
      <title>SSL Decryption Auto Tag URL to No Longer Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-auto-tag-url-to-no-longer-decrypt/m-p/562278#M113888</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am working to get SSL decryption built in our environment.&amp;nbsp; I have policies I want to start with.&lt;/P&gt;
&lt;P&gt;NoDecrypt_ByDestination (add sites as needed to dst and has NoTLSDecrypt-grp)&lt;/P&gt;
&lt;P&gt;NoDecrypt_BySource&lt;/P&gt;
&lt;P&gt;NoDecrypt_ByCategory (financial-gov-health-legal and custom URL Object Do-Not-Decrypt)&lt;/P&gt;
&lt;P&gt;TLS_Decryption - actual decrypt rule&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I'd like to see about doing if a user connects to a site/URL that can't be decrypted or fails for ANY reason. That it will then add destination or dst URL to a DAG (NoTLSDecrypt-grp) .&amp;nbsp; That DAG group is in the NoDecrypt_ByDestination.&amp;nbsp; I am thinking of accomplishing this by log forwarding profile with custom filter and built-in-action.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am ware the way this would work:&lt;/P&gt;
&lt;P&gt;1. is user would first go to site and it fail when it hits the decryption rule.&lt;/P&gt;
&lt;P&gt;2. LogFwd built-in-action is triggered and dest tagged and in NoTLSDecrypt-grp&lt;/P&gt;
&lt;P&gt;3. user then retries URL and it is bypassed by hitting NoDecrypt_ByDestination rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone configured something like this?&amp;nbsp; This way sites that fail we could periodically audit what has been tagged.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking for guiance specifically on the buit-in acitons and what to filter for in the threat logs or decryption logs for events were decryption failed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help pictured appreciated.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Adam D&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 15:44:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-auto-tag-url-to-no-longer-decrypt/m-p/562278#M113888</guid>
      <dc:creator>Adam_DiMarco</dc:creator>
      <dc:date>2023-10-18T15:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Auto Tag URL to No Longer Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-auto-tag-url-to-no-longer-decrypt/m-p/598153#M118982</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109249"&gt;@Adam_DiMarco&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am surprised no one responded to this post.&amp;nbsp; Here is a video how to do it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=WgG6Hi0T73g" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=WgG6Hi0T73g&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 17:09:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-auto-tag-url-to-no-longer-decrypt/m-p/598153#M118982</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-09-18T17:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Auto Tag URL to No Longer Decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-auto-tag-url-to-no-longer-decrypt/m-p/599551#M119217</link>
      <description>&lt;P&gt;Thanks Tom, exactly what I was looking for.&amp;nbsp; Appreciate it.&amp;nbsp; Still working to build up our SSL Decryption across our network.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 14:20:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-auto-tag-url-to-no-longer-decrypt/m-p/599551#M119217</guid>
      <dc:creator>Adam_DiMarco</dc:creator>
      <dc:date>2024-10-04T14:20:17Z</dc:date>
    </item>
  </channel>
</rss>

