<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption Whitelisting in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40271#M29551</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;If you go to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.sap.com"&gt;http://www.sap.com&lt;/A&gt;&lt;SPAN&gt; and click the login in the upper right, that brings up a login dialog box. The exact URL it is going to is: &lt;/SPAN&gt;&lt;SPAN style="color: #1a1a1a; font-size: 10pt; font-family: 'Segoe UI';"&gt;&lt;A class="jive-link-external-small" href="https://www.sap.com/content/sapcom/global/usa/en_us/registration/login.html"&gt;https://www.sap.com/content/sapcom/global/usa/en_us/registration/login.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is important to note, this works fine when you go to that url directly. Only when clicking on the link on the main page does it not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Apr 2014 18:42:27 GMT</pubDate>
    <dc:creator>bgranholm</dc:creator>
    <dc:date>2014-04-21T18:42:27Z</dc:date>
    <item>
      <title>SSL Decryption Whitelisting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40269#M29549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, I have just implemented SSL Decryption in our environment and we hit a website that appears to not work properly because of it. (It's sap.com, click on the login link in the upper right.) We don't see any errors in the firewall but the login prompt doesn't come up for us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is, is there any way for me to whitelist *.sap.com from SSL Decryption? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Apr 2014 17:26:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40269#M29549</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2014-04-21T17:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Whitelisting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40270#M29550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bgranholm,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see sap.com over https. If it is not using https, the traffic is not encrypted, hence decryption is not necessary to those websites. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case I do not have the correct URL and you see it over https, you can follow this document to exclude just one URL from being decrypted: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1241"&gt;How to Exclude a Single URL from SSL Decryption&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;This can also be done on GUI by importing the certificate of that website on to the firewall under Device&amp;gt;Certificates&amp;gt;Import and mark it for SSL Exclude.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Apr 2014 18:12:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40270#M29550</guid>
      <dc:creator>dreputi</dc:creator>
      <dc:date>2014-04-21T18:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Whitelisting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40271#M29551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;If you go to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.sap.com"&gt;http://www.sap.com&lt;/A&gt;&lt;SPAN&gt; and click the login in the upper right, that brings up a login dialog box. The exact URL it is going to is: &lt;/SPAN&gt;&lt;SPAN style="color: #1a1a1a; font-size: 10pt; font-family: 'Segoe UI';"&gt;&lt;A class="jive-link-external-small" href="https://www.sap.com/content/sapcom/global/usa/en_us/registration/login.html"&gt;https://www.sap.com/content/sapcom/global/usa/en_us/registration/login.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is important to note, this works fine when you go to that url directly. Only when clicking on the link on the main page does it not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Apr 2014 18:42:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40271#M29551</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2014-04-21T18:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Whitelisting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40272#M29552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For what it is worth, my Palo Alto Firewall 2050 running 4.1.16 has the same issue that you describe bgranholm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I click on the login link on sap.com, the link directs me to &lt;SPAN style="color: #222222; font-family: Consolas, 'Lucida Console', monospace; font-size: 12px;"&gt;&lt;A class="jive-link-external-small" href="https://accounts.sap.com/saml2/idp/sso/accounts.sap.com"&gt;https://accounts.sap.com/saml2/idp/sso/accounts.sap.com&lt;/A&gt;&lt;/SPAN&gt; which is obviously an SAML2 SSO redirect.&amp;nbsp; This never completes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dreputi's method might work depending on where the SSL is failing at.&amp;nbsp; I suppose one could alternatively create a decryption policy rule to exclude decryption of 155.56.59.145, as that is where accounts.sap.com resolves.&amp;nbsp;&amp;nbsp; If this works for you, it would allow you to decrypt other aspects of SAP without decryption the SAML server.&amp;nbsp; I would advise against a FQDN decryption rule and I will mention that this IP will likely change in the future; you will need to keep the decryption rule updated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In either case, you may need to this command from the CLI to make the change effective: &lt;STRONG&gt;debug dataplane reset ssl-decrypt certificate-cache&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; And then you may need to restart your Internet browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edwin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Apr 2014 20:49:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40272#M29552</guid>
      <dc:creator>EdwinD</dc:creator>
      <dc:date>2014-04-21T20:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption Whitelisting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40273#M29553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is what we ended up doing based on the recommendations of our SE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We created a custom URL category for whitelisting, Then put a new no-decyrpt SSL policy first which keys on the Custom URL Category.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way, if/when we discover new urls that have issues, we can just add them to the whitelist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your advice/assistance on this!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 14:28:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-whitelisting/m-p/40273#M29553</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2014-04-22T14:28:40Z</dc:date>
    </item>
  </channel>
</rss>

