<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL-decryption slow in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33448#M24525</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any news about this issue?&lt;/P&gt;&lt;P&gt;Block-Page didn't display if trying to access https webpages .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ex.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.facebook.com"&gt;http://www.facebook.com&lt;/A&gt;&lt;SPAN&gt; --&amp;gt; Block page is displaying&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://www.facebook.com"&gt;https://www.facebook.com&lt;/A&gt;&lt;SPAN&gt; --&amp;gt; No block page is displaying&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im using version 4.1.4&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jul 2012 14:35:16 GMT</pubDate>
    <dc:creator>BPERE</dc:creator>
    <dc:date>2012-07-06T14:35:16Z</dc:date>
    <item>
      <title>SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33440#M24517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have tested SSL decryption today, and I made it work. But for some reason some of the webpages that are being decrypted are extremely slow. Facebook and even support.paloaltonetworks.com are two of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I exported a CA certificate from our AD and imported it into the PA as described in a document I found on the knowledgebase.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look at the attached file for my configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more thing that is not working is the "block" page when I try to download the eicar test virus file via https.&lt;/P&gt;&lt;P&gt;I can see in the monitor/threat that the file is being blocked but I do not get the block page. Works if I open the eicar virus file via http.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions on what the problem can be?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an PA-500 with sw version 4.0.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jo Christian&lt;/P&gt;&lt;P&gt;﻿﻿&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jul 2011 11:38:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33440#M24517</guid>
      <dc:creator>jochristian</dc:creator>
      <dc:date>2011-07-21T11:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33441#M24518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I have a similar install than you, but I don't put URL categories filters in decrypt rules (I left it to 'Any') and it works like a charm.&lt;/P&gt;&lt;P&gt; Also are you using some user identification? May be with a captive portal ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jul 2011 08:22:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33441#M24518</guid>
      <dc:creator>lardsa</dc:creator>
      <dc:date>2011-07-22T08:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33442#M24519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@lardsa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have a similar setup to yourself, but I've found that SSL decryption can be very slow on some website including the PAN support portal. I've had to put a rule in to not decrypt the effected websites and the performace then returns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone from PAN explain why these performance issues are happening and what else (other than not to decrypt them) can be done to fix it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've used other web scanning products with SSL decryption and I've not experienced these sort of performance issues before.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jul 2011 09:01:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33442#M24519</guid>
      <dc:creator>ERIKS</dc:creator>
      <dc:date>2011-07-22T09:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33443#M24520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@lardsa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes I have tried setting the categories filter to "Any", but it's still a problem.&lt;BR /&gt;&lt;SPAN&gt;How does your setup work against &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://facebook.com"&gt;https://facebook.com&lt;/A&gt;&lt;SPAN&gt;? Take minutes for my setup to open it up when ssl decrypt is enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes we use user identification (but not captive portal).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jo Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jul 2011 09:15:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33443#M24520</guid>
      <dc:creator>jochristian</dc:creator>
      <dc:date>2011-07-22T09:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33444#M24521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Only website that shows slowness for my users with decryption enabled is Google Mail and only with Chrome (IE &amp;amp; Firefox are ok).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a support ticket opened for that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jul 2011 09:20:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33444#M24521</guid>
      <dc:creator>lardsa</dc:creator>
      <dc:date>2011-07-22T09:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33445#M24522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I tested with IE and it things seems to be abit smoother. I always use Chrome.&lt;/P&gt;&lt;P&gt;But what can be the reason for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Btw does the block page work for you when trying to open &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://secure.eicar.org/eicar_com.zip"&gt;https://secure.eicar.org/eicar_com.zip&lt;/A&gt;&lt;SPAN&gt; ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If antivirus profile is enabled. I see in the log that the file is blocked but I don't get the webpage.&lt;/P&gt;&lt;P&gt;Chrome just hang trying to load the "page/file".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Work as it should if I try to download the file when not using ssl/https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jo Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jul 2011 11:53:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33445#M24522</guid>
      <dc:creator>jochristian</dc:creator>
      <dc:date>2011-07-22T11:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33446#M24523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok I confirm Block page is not appearing while it does on non SSL one.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jul 2011 13:27:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33446#M24523</guid>
      <dc:creator>lardsa</dc:creator>
      <dc:date>2011-07-22T13:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33447#M24524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you retry since 4.0.4 was released ? It has some SSL fixes in release notes ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Aug 2011 09:23:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33447#M24524</guid>
      <dc:creator>lardsa</dc:creator>
      <dc:date>2011-08-03T09:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33448#M24525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any news about this issue?&lt;/P&gt;&lt;P&gt;Block-Page didn't display if trying to access https webpages .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ex.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.facebook.com"&gt;http://www.facebook.com&lt;/A&gt;&lt;SPAN&gt; --&amp;gt; Block page is displaying&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://www.facebook.com"&gt;https://www.facebook.com&lt;/A&gt;&lt;SPAN&gt; --&amp;gt; No block page is displaying&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im using version 4.1.4&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 14:35:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33448#M24525</guid>
      <dc:creator>BPERE</dc:creator>
      <dc:date>2012-07-06T14:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33449#M24526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the no block page on ssl issue as well&lt;BR /&gt;4.0.9 - 4020&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 16:17:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33449#M24526</guid>
      <dc:creator>choff123</dc:creator>
      <dc:date>2012-07-06T16:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33450#M24527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Common Name says www.facebook.com so it shouldnt be that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However Facebook seems to use a new cert issued 2012-06-21 that perhaps for some reason isnt recognized by PA as a visit to Facebook?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the blockpage not visible even if you do SSL termiantion (ssl-proxy) in your PA towards your clients (because then the PA can look inside the encrypted traffic and see the actual GET/HEAD request and the URI used there)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2012 14:18:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33450#M24527</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-07T14:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33451#M24528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same issue with other sites like www.flickr.com. Accessing flickr in http, the block page is displaying and trying to access the same page in https, no block page is displaying. As SSL Termination, I’m using ssl-forward-proxy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 08:19:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33451#M24528</guid>
      <dc:creator>BPERE</dc:creator>
      <dc:date>2012-07-09T08:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33452#M24529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have experienced the same issue with block pages and https. From the cli run the following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;config&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11.818181991577148px; background-color: #ffffff;"&gt;set deviceconfig setting ssl-decrypt url-proxy yes &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11.818181991577148px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11.818181991577148px; background-color: #ffffff;"&gt;This blocks ssl pages, but shows ip:port and category as any in the traffic log.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11.818181991577148px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11.818181991577148px; background-color: #ffffff;"&gt;Ben&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 12:20:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33452#M24529</guid>
      <dc:creator>bnelson</dc:creator>
      <dc:date>2012-07-09T12:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33453#M24530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Benjamin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Blocks ssl pages and display the block page?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 08:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33453#M24530</guid>
      <dc:creator>BPERE</dc:creator>
      <dc:date>2012-07-10T08:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-decryption slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33454#M24531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@BPERE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sorry, this is not part of the blocking of the https web page. The blocking is still performed by the URL Filtering engine. It does allow the Palo Alto firewall to display the block page rather than a default browser error page. In the URL filtering log it will display the ip:port rather than &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.facebook.com"&gt;https://www.facebook.com&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 12:58:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-slow/m-p/33454#M24531</guid>
      <dc:creator>bnelson</dc:creator>
      <dc:date>2012-07-10T12:58:58Z</dc:date>
    </item>
  </channel>
</rss>

