<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH decryption policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2221#M1650</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have recently deployed PA devices in our network as IPS. We have configured SSH proxy and provide an exception with negate policy for the hosts. I have a basic question regarding decryption rule. I am assuming all rules work like firewalls with src zone + hosts (if any) + dst zone + dst hosts (if any) and services. Is it true for decryption policies as well? We have configured policy to bypass SSH proxy and add src OR dst with "negate" checked. The policies were configured by someone else but I am somehow confused as I am believing that the policy works as src and dst and not src or dst. Please help me understand.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Sep 2012 07:47:54 GMT</pubDate>
    <dc:creator>Sly_Cooper</dc:creator>
    <dc:date>2012-09-04T07:47:54Z</dc:date>
    <item>
      <title>SSH decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2221#M1650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have recently deployed PA devices in our network as IPS. We have configured SSH proxy and provide an exception with negate policy for the hosts. I have a basic question regarding decryption rule. I am assuming all rules work like firewalls with src zone + hosts (if any) + dst zone + dst hosts (if any) and services. Is it true for decryption policies as well? We have configured policy to bypass SSH proxy and add src OR dst with "negate" checked. The policies were configured by someone else but I am somehow confused as I am believing that the policy works as src and dst and not src or dst. Please help me understand.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 07:47:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2221#M1650</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2012-09-04T07:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2222#M1651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stuff in the same decryption policy works as AND, while compared to a different policy it works as OR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it should be the same execution path as security policies have regarding top-down first-match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A tricky part when it comes to decryption policies might be the "allow encrypted traffic" which a rule can have in case it cannot decrypt the matching traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a session (or packet) matches your particular decryption rule and "allow encrypted traffic" is not set then the flow will be blocked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 11:40:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2222#M1651</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-09-04T11:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2223#M1652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For my own sanity, I've never used the negate box. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the scenario, I would create a policy with the exception list as a "no-decypt" and place it above the decryption rule. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 15:29:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2223#M1652</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2012-09-04T15:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2224#M1653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. The policy had been configured by different admin and hence I am tying to understand. Yes it makes sense and easy to have two policies with one for SSH proxy and another for bypass. Do you seen any issue with negate? I guess the same policy is acting like SSH proxy all except the negates hosts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 15:40:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2224#M1653</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2012-09-04T15:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2225#M1654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am new to Palo Alto firewalls but from firewall experience even I think the policy works with src and dst. I have also opened up case with support and waiting to get confirmation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 15:42:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2225#M1654</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2012-09-04T15:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2226#M1655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It really just comes down to preference. It should work either way, but if someone comes in behind to troubleshoot an problem, it's easier to understand the no-decrypt versus the negate visually. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 16:34:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2226#M1655</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2012-09-04T16:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2227#M1656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Coming to my original question.... How do you read policy below? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zone Trust -&amp;gt; Src A + B (negate) -&amp;gt; to Zone Untrust Dst X, Y , Z (negate) -&amp;gt; Decrypt -&amp;gt; Type SSH proxy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 09:24:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2227#M1656</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2012-09-05T09:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2228#M1657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I find it harder to read...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But my intepretation is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srczone: trust&lt;/P&gt;&lt;P&gt;dstzone: untrust&lt;/P&gt;&lt;P&gt;srcaddress: any but A or B&lt;/P&gt;&lt;P&gt;dstaddress: any but X, Y or Z&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;unless you meant that you negated B and Z only and not all the selected ip/ranges :smileysilly:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 09:28:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2228#M1657</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-09-05T09:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decryption policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2229#M1658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically the host are added (negate) to bypass the SSH proxy. Everything is working fine. But I was only confused on how it is interpreted. Is it src &lt;STRONG&gt;"and"&lt;/STRONG&gt; dst negate pair OR src &lt;STRONG&gt;"or"&lt;/STRONG&gt; dst negate individual hosts. Since it is working I am assuming that for negate it is not considering src and dst pair like standard policy. &lt;/P&gt;&lt;P&gt;T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 09:36:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption-policy/m-p/2229#M1658</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2012-09-05T09:36:58Z</dc:date>
    </item>
  </channel>
</rss>

