<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking page for https traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-page-for-https-traffic/m-p/27177#M19825</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx for your answer. Will test that as faster as possible &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;v.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Jun 2014 07:42:20 GMT</pubDate>
    <dc:creator>VinceM</dc:creator>
    <dc:date>2014-06-03T07:42:20Z</dc:date>
    <item>
      <title>Blocking page for https traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-page-for-https-traffic/m-p/27175#M19823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently on PA-2050 in version 5.0.9.&lt;/P&gt;&lt;P&gt;Creating Web secur profile for test categorie (with PAn-DB).&lt;/P&gt;&lt;P&gt;If trying to access blocked page in http =&amp;gt; block page (NICE !!)&lt;/P&gt;&lt;P&gt;If trying to access blocked page in https =&amp;gt; Page "session has been reste" - default browser block page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would like to have the palo block page everytime.&lt;/P&gt;&lt;P&gt;Can you help me to configure that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2014 15:03:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-page-for-https-traffic/m-p/27175#M19823</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-06-02T15:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking page for https traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-page-for-https-traffic/m-p/27176#M19824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please confirm that Decryption policy is configured on the PAN FW or not, if not, then you have to configure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A certificate on the PAN Device. One of the following:&lt;UL style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;LI style="margin-top: 0.5ex; margin-bottom: 0.5ex; font-weight: inherit; font-style: inherit; font-family: inherit; list-style-type: inherit;"&gt;A self-signed/self-generated certificate which is a CA certificate configured for Forward Trust / Forward Untrust use (as relevant to deployment requirements)&lt;BR /&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;Note:&lt;/STRONG&gt; if using a self-signed/&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;sef&lt;/SPAN&gt;-generated certificate it will be necessary to import this certificate into the client machine's certificate store to avoid unwanted browser certificate errors&lt;/LI&gt;&lt;LI&gt;An intermediate CA certificate installed on the PAN Device which was generated by an organization's internal CA also configured for Forward Trust / Forward Untrust use&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even though you haven't configured a decryption policy, The PAN firewall will internally decrypt the packet to push the BLOCK page notification in front of the end user, during handshake.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4901"&gt;How to Configure the Palo Alto Networks Device to Serve a URL Response page Over an HTTPS Session without SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, as per my experience, you will get the best result with a decryption policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2014 16:36:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-page-for-https-traffic/m-p/27176#M19824</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-06-02T16:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking page for https traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-page-for-https-traffic/m-p/27177#M19825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx for your answer. Will test that as faster as possible &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;v.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2014 07:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-page-for-https-traffic/m-p/27177#M19825</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-06-03T07:42:20Z</dc:date>
    </item>
  </channel>
</rss>

