<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: missing block-url response page in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24131#M17587</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I replicated this with 5.0.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we don't use ssl decryption no page comes.(web page cannot be displayed)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we use ssl decryption we see block page.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Jun 2013 17:16:08 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-06-03T17:16:08Z</dc:date>
    <item>
      <title>missing block-url response page</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24128#M17584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a very common security rule permitting all traffic in for 80, 8080 and 443 ports, no matter the application&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The attached URL security profile denies all url categories except for one (custom).&lt;/P&gt;&lt;P&gt;Now I've noticed not to be able to get the expected block page each time a try to access a web site, specifically I can obtain the response page only when the detected application is "web-browsing" but not, i.e, when it's ssl, facebook, gmail etc.&lt;/P&gt;&lt;P&gt;So when I go to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;gmail.com&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;www.microsoft.com&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;facebook.com&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get the block page.&lt;/P&gt;&lt;P&gt;While when i try with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A class="jive-link-external-small" href="https://facebook.com"&gt;https://facebook.com&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A class="jive-link-external-small" href="https://gmail.com"&gt;https://gmail.com&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A class="jive-link-external-small" href="https://kb.bluecoat.com"&gt;https://kb.bluecoat.com&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just get the browser error page but NO block page.&lt;/P&gt;&lt;P&gt;This is the TRAFFIC log&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/6743_pastedImage_3.png" style="width: 805px; height: 272px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;while this is the URL log&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/6744_pastedImage_4.png" style="width: 995px; height: 269px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as you can see there's no match for anything else than port 80.&lt;/P&gt;&lt;P&gt;So I've tried to setup an ssl decryption policy&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/6745_pastedImage_5.png" style="width: 1073px; height: 25px;" /&gt;&lt;/P&gt;&lt;P&gt;tha shoulfd catch anything for that source ip address, but nothing changes, I keep on getting a block page only when traffic is web-browsing but as you might understand is quite boring for users, whose resulting experience having the page not showing but without knowing the reason....&lt;/P&gt;&lt;P&gt;Is this the expected behaviour?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Manuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 15:28:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24128#M17584</guid>
      <dc:creator>errevisystem</dc:creator>
      <dc:date>2013-06-03T15:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: missing block-url response page</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24129#M17585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Know that in some version, there is a bug wich not allow to send reponse page if tarffic is https.&lt;/P&gt;&lt;P&gt;What is your version ?&lt;/P&gt;&lt;P&gt;Try to upgrade to last one either 5.0.5 or 4.1.12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 15:33:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24129#M17585</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-06-03T15:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: missing block-url response page</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24130#M17586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I forgot, my PANOS version is 5.0.4.&lt;/P&gt;&lt;P&gt;Don't know if this bug could somehow be related:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;46649&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;When denying a web session with a response page, the firewall did not perform a&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;proper close for the TCP connection, causing the client to remain half open. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but theoretically it should have been solved starting with 5.0.4...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 15:34:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24130#M17586</guid>
      <dc:creator>errevisystem</dc:creator>
      <dc:date>2013-06-03T15:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: missing block-url response page</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24131#M17587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I replicated this with 5.0.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we don't use ssl decryption no page comes.(web page cannot be displayed)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we use ssl decryption we see block page.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 17:16:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24131#M17587</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-03T17:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: missing block-url response page</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24132#M17588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default, you can't display block response page with HTTPS websites.&lt;/P&gt;&lt;P&gt;There are two ways to show it.&lt;/P&gt;&lt;P&gt;One is to use ssl-decryption rule, another is to enable url-proxy.&lt;/P&gt;&lt;P&gt;For url-proxy in detail, please refer to &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4901"&gt;How to Configure the Palo Alto Networks Device to Serve a URL Response page Over an HTTPS Session without SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my PA-200 with 5.0.5 works fine by url-proxy and no decryption rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 13:07:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24132#M17588</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2013-06-05T13:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: missing block-url response page</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24133#M17589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi emr,&lt;/P&gt;&lt;P&gt;I had tried before with ssl-decryption (see my previous post) and right now with the method according to your link, I found it very useful and in my opinion that should be the default behaviour, I wonder why it's not.&lt;/P&gt;&lt;P&gt;Unfortunately In both cases I cannot get any block page...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 15:53:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24133#M17589</guid>
      <dc:creator>errevisystem</dc:creator>
      <dc:date>2013-06-05T15:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: missing block-url response page</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24134#M17590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update: just retried with another platform 5.0.5 and got it working enabling ssl-decrypt url-proxy yes&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 16:22:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/missing-block-url-response-page/m-p/24134#M17590</guid>
      <dc:creator>errevisystem</dc:creator>
      <dc:date>2013-06-05T16:22:49Z</dc:date>
    </item>
  </channel>
</rss>

