<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Facebook is not displaying its page/images properly when SSL Decryption is enabled in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36170#M26587</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A lot of sites like this don't like you to have a SSL decrypt rule in place. I have had the same problem with Dropbox and in the end I had to put a no-decrypt rule in specifically for the people who use that service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, the site is saying that it doesn't like you doing something in the middle of the transmitting, like SSL decryption. Those sites will generally give you a reduced webpage much like what your screenshot showed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try going to your Decryption rules and adding one that says, Any source, any destination, URL category as only Facebook, no decrypt and ssl-forward Proxy. If that works you may want to restrict it down to specific sources or specific destination zone.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Jun 2013 11:14:52 GMT</pubDate>
    <dc:creator>JRussell</dc:creator>
    <dc:date>2013-06-19T11:14:52Z</dc:date>
    <item>
      <title>Facebook is not displaying its page/images properly when SSL Decryption is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36168#M26585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Facebook is not displaying its page/images properly when SSL Decryption is enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas why ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Note: I have a rule allowing ANY destination with ANY application with ANY service, also another rule i tried was with ANY destination with Explicitly allowing all facebook applications on service ANY, and yet it didn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My SSL Forward certificate is 1024-bit sha-1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="pa-ssl-decryption.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6979_pa-ssl-decryption.jpg" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 08:42:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36168#M26585</guid>
      <dc:creator>AKamal</dc:creator>
      <dc:date>2013-06-19T08:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook is not displaying its page/images properly when SSL Decryption is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36169#M26586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using any URL categories in the decrypt rule.&lt;/P&gt;&lt;P&gt;How abt using IE/Chrome?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 10:18:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36169#M26586</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-06-19T10:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook is not displaying its page/images properly when SSL Decryption is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36170#M26587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A lot of sites like this don't like you to have a SSL decrypt rule in place. I have had the same problem with Dropbox and in the end I had to put a no-decrypt rule in specifically for the people who use that service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, the site is saying that it doesn't like you doing something in the middle of the transmitting, like SSL decryption. Those sites will generally give you a reduced webpage much like what your screenshot showed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try going to your Decryption rules and adding one that says, Any source, any destination, URL category as only Facebook, no decrypt and ssl-forward Proxy. If that works you may want to restrict it down to specific sources or specific destination zone.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 11:14:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36170#M26587</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2013-06-19T11:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook is not displaying its page/images properly when SSL Decryption is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36171#M26588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ehm woot?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason the dropbox client doesnt work is that the dropbox client has a hardcoded ssl cert that if this doesnt match (as when ssl decryption is in progress) the client refuse to connect - same goes with windowsupdate (that is the client - not when used through webbrowser) for that matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However the dropbox through webbrowser will still work even if you do ssl decryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding facebook you should check your browser that the facebook server cert isnt already preloaded. I think both firefox and google chrome started to do something like that last year or so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you then need to do, except adding the cert used to create these MITM ssl certs as a trusted CA, is to clear any preloaded server certs regarding facebook.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also note that facebook uses various CDN which also must be reachable by the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Except for this - how is your ssl decrypt rule setup?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 19:08:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36171#M26588</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-06-19T19:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook is not displaying its page/images properly when SSL Decryption is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36172#M26589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No. I have a rule that says Decrypt all sites. Unless I have another rule in saying no-decrypt on dropbox then the website does not work. Gives an SSL error. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know about the Dropbox client and the hardcoded SSl cert as I had to change that to get it to work, but this is a website both &lt;STRONG style="font-size: 11px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="21660" data-username="ksabry" href="https://live.paloaltonetworks.com/people/ksabry" id="jive-2166043056970375091576" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; text-decoration: underline; color: #316989;"&gt;ksabry&lt;/A&gt;&lt;/STRONG&gt; and I are talking about, not any client software. And in these cases if you have a decrypt all sites rule in place, then you would need a no-decrypt rule for certain sites. Such as banking sites for instance. They don't like it when you decrypt their traffic before it gets to the end point and will not allow you to log on. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 08:06:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36172#M26589</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2013-06-20T08:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook is not displaying its page/images properly when SSL Decryption is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36173#M26590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unless the bank uses a client cert (which very few does) - how would the bank be able to detect that the ssl traffic is being intercepted at the client end according to you ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the Facebook problem - verify if they only accept TLS 1.1 or newer? If so then PA might lack support to handle TLS 1.1 and newer ssl based communication.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 08:20:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36173#M26590</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-06-20T08:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook is not displaying its page/images properly when SSL Decryption is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36174#M26591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well perhaps I should have quantified that statement a little bit. OUR banking sites don't like it when the traffic is decrypted before getting to the end point. And yes, ours does use Cert. We have a card reader that we have to pull the certs from a card they send us to get it to all work properly. But that is getting a bit off topic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I was suggesting is to try a no-decrypt rule to see if that allows him through as that is what worked for me in other cases. Not facebook though as we block that across the board.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 08:32:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36174#M26591</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2013-06-20T08:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook is not displaying its page/images properly when SSL Decryption is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36175#M26592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A __default_attr="15536" __jive_macro_name="user" class="jive_macro jive_macro_user" data-objecttype="3" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; , &lt;A __default_attr="3245" __jive_macro_name="user" class="jive_macro jive_macro_user" data-objecttype="3" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; &amp;amp; &lt;A __default_attr="11199" __jive_macro_name="user" class="jive_macro jive_macro_user" data-objecttype="3" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt;I specified in my decryption rule to match on all categories (I added them all explicitly) &lt;/P&gt;&lt;P&gt;I tried with IE, Chrome &amp;amp; Firefox and seems that the problem is with Firefox only!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 14:46:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-is-not-displaying-its-page-images-properly-when-ssl/m-p/36175#M26592</guid>
      <dc:creator>AKamal</dc:creator>
      <dc:date>2013-06-24T14:46:39Z</dc:date>
    </item>
  </channel>
</rss>

