<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Decrypt traffice in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-traffice/m-p/37543#M27522</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a reason you wouldn't want to decrypt traffic like:&amp;nbsp; Shopping&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jun 2012 20:05:29 GMT</pubDate>
    <dc:creator>jorge</dc:creator>
    <dc:date>2012-06-14T20:05:29Z</dc:date>
    <item>
      <title>Decrypt traffice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-traffice/m-p/37543#M27522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a reason you wouldn't want to decrypt traffic like:&amp;nbsp; Shopping&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2012 20:05:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-traffice/m-p/37543#M27522</guid>
      <dc:creator>jorge</dc:creator>
      <dc:date>2012-06-14T20:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypt traffice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-traffice/m-p/37544#M27523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my opinion, specially when it comes using PA towards Internet, you should decrypt everything and stuff that cannot be decrypted shouldnt be allowed through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Windowsupdate can be handled separately (for example if you setup a WSUS and only let WSUS server go for windowsupdate on the Internet using appid windowsupdate).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tricky part is how this cert whitelist which PA uses affects decryption. Will this whitelist always overrule decrypt settings or will a "deny flows which cannot be decrypted" overrule the whitelist - perhaps someone from PA could clearify?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway - there might be countries/places where you are not supposed/allowed to decrypt stuff on the road. Banking/Financial seems to be a common example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise it can be for performance reasons which you dont want to decrypt certain categories but in my opinion this is bad...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2012 21:15:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-traffice/m-p/37544#M27523</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-14T21:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypt traffice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-traffice/m-p/37545#M27524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Your environment may wary from mine. &lt;BR /&gt;My reason for using decrypt is to see what hides inside.&amp;nbsp; Checking the traffic is an attempt to look for and stop unwanted traffic.&lt;/P&gt;&lt;P&gt;So is it likely the “Shopping” may contain things that you do not want in your environment?&lt;BR /&gt;My 5 cents is that “Shopping” is not likely to contain malware in the encrypted stream.&amp;nbsp; “Shopping” is likely to have some payment options (credit card numbers ). Are you allowed to view those ?&lt;BR /&gt;Decrypt may break some payment options (used in “shopping”).&amp;nbsp; &lt;BR /&gt;Or you may want to limit or block shopping during work hours ?&lt;/P&gt;&lt;P&gt;Decrypting traffic may also have legal consequences. Your geographic location and laws that apply to your company, may influence your outcome. US and EU view of “privacy” are somewhat different.&lt;/P&gt;&lt;P&gt;/ Regards Paul M&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2012 07:55:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-traffice/m-p/37545#M27524</guid>
      <dc:creator>pnotpub</dc:creator>
      <dc:date>2012-06-15T07:55:02Z</dc:date>
    </item>
  </channel>
</rss>

