<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Where to find information about  SSL decryption is (not) required to identified traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/where-to-find-information-about-ssl-decryption-is-not-required/m-p/1234701#M124837</link>
    <description>&lt;P&gt;Hello guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to know if there is a resource where I can find if SSL decryption is required or not to identified the APP traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have this information inside&amp;nbsp;Palo Alto Networks Content Update mail but I don't find this information in applipedia or somewhere else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anybody have an idea&amp;nbsp; ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Alexis&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jul 2025 14:39:02 GMT</pubDate>
    <dc:creator>A.Molter</dc:creator>
    <dc:date>2025-07-25T14:39:02Z</dc:date>
    <item>
      <title>Where to find information about  SSL decryption is (not) required to identified traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-to-find-information-about-ssl-decryption-is-not-required/m-p/1234701#M124837</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to know if there is a resource where I can find if SSL decryption is required or not to identified the APP traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have this information inside&amp;nbsp;Palo Alto Networks Content Update mail but I don't find this information in applipedia or somewhere else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anybody have an idea&amp;nbsp; ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Alexis&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 14:39:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-to-find-information-about-ssl-decryption-is-not-required/m-p/1234701#M124837</guid>
      <dc:creator>A.Molter</dc:creator>
      <dc:date>2025-07-25T14:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Where to find information about  SSL decryption is (not) required to identified traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-to-find-information-about-ssl-decryption-is-not-required/m-p/1234787#M124849</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/877616189"&gt;@A.Molter&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSL Decryption is required for application traffic that is encrypted by SSL/TLS, if you would like to truly identify what the underlying application is. If you go onto your monitor tab and view traffic from your trust zone to the untrust zone, you will likely find a number of connections that have the app-id "ssl". Without decryption, you don't really know what type of application the connection is because the firewall can't inspect the encrypted payload. The employee could be watching a cnn video or a youtube video.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend taking a look at how much SSL traffic traverses any firewall you might have that sits at the edge. Head over to your ACC tab on your firewall. Then click on SSL activity and set the time frame to last 90 days. How much SSL traffic do you see? How does it compare to other traffic? There is all your application traffic that hides behind encryption.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend reading &lt;A href="https://docs.paloaltonetworks.com/network-security/decryption/administration/decryption-overview" target="_self"&gt;Decryption Basics&lt;/A&gt; and &lt;A href="https://docs.paloaltonetworks.com/best-practices/10-2/decryption-best-practices" target="_self"&gt;Decryption best practices.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 15:45:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-to-find-information-about-ssl-decryption-is-not-required/m-p/1234787#M124849</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-07-28T15:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Where to find information about  SSL decryption is (not) required to identified traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-to-find-information-about-ssl-decryption-is-not-required/m-p/1234854#M124852</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for all thoses advices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I just want to know if there is a documentation about what applications required decryption to be identified and what not.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="--l --r container-target"&gt;I am surprised to find this information inside&amp;nbsp;Palo Alto Networks Content Update newsletter but not in the applipedia.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="--l --r container-target"&gt;This can be helpful to understand what applications can be block or allow in network without decryption.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 06:33:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-to-find-information-about-ssl-decryption-is-not-required/m-p/1234854#M124852</guid>
      <dc:creator>A.Molter</dc:creator>
      <dc:date>2025-07-29T06:33:23Z</dc:date>
    </item>
  </channel>
</rss>

