<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why can't the firewall present a Response Page on Non-Decrypted SSL Web sites? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24159#M17611</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I replied in #1 : a block/error message requires the original page to be replaced by error page and doing that cannot be done without decrypting since the original page is inside the encrypted connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Apr 2015 08:21:02 GMT</pubDate>
    <dc:creator>cpainchaud</dc:creator>
    <dc:date>2015-04-09T08:21:02Z</dc:date>
    <item>
      <title>Why can't the firewall present a Response Page on Non-Decrypted SSL Web sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24152#M17604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to understand why users can't get a URL Filtering Response Page when they go to SSL-based Web Sites that are not being decrypted by the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 15:18:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24152#M17604</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2015-04-08T15:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the firewall present a Response Page on Non-Decrypted SSL Web sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24153#M17605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it's the purpose of SSL (encrypted) webpages : no one can mess with the content of your website unless he can do a Man in the Middle to decrypt and listen, even change the content. In order to make a nice error message to user any product in the market needs to replace original content of the webpage with that error message and it's only doable if decryption is done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when we can't decrypt then we drop traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 16:53:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24153#M17605</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-04-08T16:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the firewall present a Response Page on Non-Decrypted SSL Web sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24154#M17606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;URL filtering is done after the session is setup when the http request is made.&amp;nbsp; By this point the session is encrypted including the payload of the url text.&amp;nbsp; So we require decryption in order to read the URL and check the category and apply rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 20:04:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24154#M17606</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-04-08T20:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the firewall present a Response Page on Non-Decrypted SSL Web sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24155#M17607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your answer.&amp;nbsp; I understand why we must SSL Decrypt to be able to see the actual HTTP Get Request.&amp;nbsp; What I don't understand is why the firewall doesn't display a URL Response Page for URL Categories that have an action of either Block, Continue or Override for sites that are SSL but not decrypted by the firewall.&amp;nbsp; What does the firewall do (technically) when it is presented a site that is block, continue or override by the URL Filtering Profile in order for it to present a Response Page?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 20:18:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24155#M17607</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2015-04-08T20:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the firewall present a Response Page on Non-Decrypted SSL Web sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24156#M17608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope below link may help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4901"&gt;How to Serve a URL Response Page Over an HTTPS Session Without SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 22:39:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24156#M17608</guid>
      <dc:creator>jthakur</dc:creator>
      <dc:date>2015-04-08T22:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the firewall present a Response Page on Non-Decrypted SSL Web sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24157#M17609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I already looked at that thread and if you read it closely and implement it, the firewall is actually decrypting the HTTPS sessions. The title is very misleading. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 23:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24157#M17609</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2015-04-08T23:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the firewall present a Response Page on Non-Decrypted SSL Web sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24158#M17610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using Firefox and see message "(Error code: ssl_error_rx_record_too_long) ", then it means firewall has sent the response page however the browser expected the SSL\TLS handshake. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can take a packet capture on client machine to see what's happening.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 23:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24158#M17610</guid>
      <dc:creator>jthakur</dc:creator>
      <dc:date>2015-04-08T23:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the firewall present a Response Page on Non-Decrypted SSL Web sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24159#M17611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I replied in #1 : a block/error message requires the original page to be replaced by error page and doing that cannot be done without decrypting since the original page is inside the encrypted connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2015 08:21:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24159#M17611</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-04-09T08:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the firewall present a Response Page on Non-Decrypted SSL Web sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24160#M17612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it!&amp;nbsp; Thank you very much! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2015 12:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-can-t-the-firewall-present-a-response-page-on-non-decrypted/m-p/24160#M17612</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2015-04-09T12:47:20Z</dc:date>
    </item>
  </channel>
</rss>

