<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application Blocking page for HTTPS traffic through Web Proxy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20417#M14889</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is expected behavior. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When configuring file blocking or URL filtering profiles for a policy and the action Continue is configured to prompt users before downloading files or accessing certain URLs, the continue page will not appear when accessing HTTPS sites. This will occurs if the firewall is configured with SSL decryption and the user’s browser is using a proxy server. The only workaround for this issue at this time is to disable proxy on the browser. The browsers that were tested for this issue include Internet Explorer versions 7 and 8, other browsers may also have this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll work on a getting this in our KB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;P&gt;PaloAlto Networks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Nov 2012 22:50:44 GMT</pubDate>
    <dc:creator>dburns</dc:creator>
    <dc:date>2012-11-20T22:50:44Z</dc:date>
    <item>
      <title>Application Blocking page for HTTPS traffic through Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20414#M14886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Hello,&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;I experienced an issue with 'application blocking page' for https traffic through web proxy.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;The firewall is configured to decrypt the HTTPS traffic.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Layout : Client -- Palo Alto FW -- Web proxy (Squid)&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN&gt;If the traffic (https session like &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.facebook.com"&gt;https://www.facebook.com&lt;/A&gt;&lt;SPAN&gt;) is sent directly to Internet, I receive the 'Application Blocked page' in the browser.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;If the traffic goes through the proxy (explicit configuration in the browser), I don't receive &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;the 'Application Blocked page' in the browser.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Is it the default behaviour ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;How can I change this ??&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;HA&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2012 20:53:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20414#M14886</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-11-20T20:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocking page for HTTPS traffic through Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20415#M14887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi HA...Are you matching the application &amp;amp; action=deny, or are you using URL filtering to match the domain and block?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2012 21:50:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20415#M14887</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-11-20T21:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocking page for HTTPS traffic through Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20416#M14888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I match at the application layer.&lt;/P&gt;&lt;P&gt;Basically, at the end of the rule base, I have a rule which block everything.&lt;/P&gt;&lt;P&gt;In the traffic log file, I clearly see 'facebook-base', action : deny.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2012 21:57:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20416#M14888</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-11-20T21:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocking page for HTTPS traffic through Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20417#M14889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is expected behavior. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When configuring file blocking or URL filtering profiles for a policy and the action Continue is configured to prompt users before downloading files or accessing certain URLs, the continue page will not appear when accessing HTTPS sites. This will occurs if the firewall is configured with SSL decryption and the user’s browser is using a proxy server. The only workaround for this issue at this time is to disable proxy on the browser. The browsers that were tested for this issue include Internet Explorer versions 7 and 8, other browsers may also have this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll work on a getting this in our KB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;P&gt;PaloAlto Networks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2012 22:50:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20417#M14889</guid>
      <dc:creator>dburns</dc:creator>
      <dc:date>2012-11-20T22:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Application Blocking page for HTTPS traffic through Web Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20418#M14890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dominic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, thanks for your help.&lt;/P&gt;&lt;P&gt;Any plan to change this behaviour in the future ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hedi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 09:16:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-blocking-page-for-https-traffic-through-web-proxy/m-p/20418#M14890</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-11-21T09:16:47Z</dc:date>
    </item>
  </channel>
</rss>

