<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Decryption Policy - Blocking things such as Facebook in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-blocking-things-such-as-facebook/m-p/32738#M23983</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;We recently discovered that due to Facebook now being &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow"&gt;https://&lt;/A&gt;&lt;SPAN&gt; that my users can get out to Facebook when using Internet Explorer.&amp;nbsp; This actually cause quite an issue due to a bug also getting in. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I configure the decryption policy to get in to the session and block the traffic?&amp;nbsp; From what I'm reading I have to configure this to block https sites?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance or advice would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Sep 2014 14:04:14 GMT</pubDate>
    <dc:creator>kaysun</dc:creator>
    <dc:date>2014-09-24T14:04:14Z</dc:date>
    <item>
      <title>Decryption Policy - Blocking things such as Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-blocking-things-such-as-facebook/m-p/32738#M23983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;We recently discovered that due to Facebook now being &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow"&gt;https://&lt;/A&gt;&lt;SPAN&gt; that my users can get out to Facebook when using Internet Explorer.&amp;nbsp; This actually cause quite an issue due to a bug also getting in. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I configure the decryption policy to get in to the session and block the traffic?&amp;nbsp; From what I'm reading I have to configure this to block https sites?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance or advice would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 14:04:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-blocking-things-such-as-facebook/m-p/32738#M23983</guid>
      <dc:creator>kaysun</dc:creator>
      <dc:date>2014-09-24T14:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption Policy - Blocking things such as Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-blocking-things-such-as-facebook/m-p/32739#M23984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kaysun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following document will help you to configure SSL decryption.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1412"&gt;How to Implement SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know for any query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 14:06:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-blocking-things-such-as-facebook/m-p/32739#M23984</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-24T14:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption Policy - Blocking things such as Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-blocking-things-such-as-facebook/m-p/32740#M23985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="4858" data-username="kaysun" href="https://live.paloaltonetworks.com/people/kaysun" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;kaysun&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="padding: 0px 3px 0px 0px; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. PAN is having app-ID for &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;facebook&lt;/SPAN&gt;. Hence, you can block &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;facebook&lt;/SPAN&gt; through a deny rule, without having SSL decryption in place. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;we&lt;/SPAN&gt; have multiple application-ID for &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;facebook&lt;/SPAN&gt; to have more granular control.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="facebook-app.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15734_facebook-app.jpg" style="height: 100px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. In general, for HTTPS (SSL) connection, PAN will not be able to verify the content of the packet. Hence, you may use the certificate name &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;through URL filtering) to control that traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 14:23:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-blocking-things-such-as-facebook/m-p/32740#M23985</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-24T14:23:33Z</dc:date>
    </item>
  </channel>
</rss>

