<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Current situation with Dropbox? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4305#M3187</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all, is it just the dropbox client you want to bypass or anything that has to do with dropbox?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because if its the later then you can do this exclude in the GUI where you setup the decrypt rules (dont ssl terminate for *.dropbox.com). Also look in the logs if dropbox is using some other domains today.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Jun 2013 08:42:46 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-06-04T08:42:46Z</dc:date>
    <item>
      <title>Current situation with Dropbox?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4301#M3183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the current "state" with PAN firewalls when it comes to decrypting Dropbox traffic? I found a lot of threads on the forum, some with contradicting information. It was said that Dropbox was put on an internal ssl-exclude list so the firewall wouldn't decrypt it, in a later post it was said it has been removed from the list again. Generally, the information is quite old. In yet another post it was suggested to put *.dropbox.com into the ssl-exclude list manually. Confusing....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried decrypting Dropbox but I failed. The Dropbox client reports it is unable to establish a secure connection, so I figure there are still issues? What is the current situation? Can Dropbox be decrypted? If not, what is the proposed way of excluding it (custom URL category with *.dropbox.com? put *.dropbox.com in the ssl-exclude-cert list?)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Jun 2013 15:29:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4301#M3183</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-06-02T15:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: Current situation with Dropbox?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4302#M3184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a command (which I forgot) you can run in the CLI to see the current exclude list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding dropbox the dropbox client can be decrypted HOWEVER it seems that dropbox is using preloaded certificates (similar to windowsupdate) which gives that it will refuse to work when decrypted on the road (because the cert which is being sent to the client is not the real dropbox cert but the PA cert used for decryption).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The decryption on the other hand works if using a webbrowser to reach your dropbox account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to make the dropbox client to work you must exclude the dropbox cert from being terminated. The downside of this is of course that the files up/downloaded to/from dropbox wont be inspected by the PA antivirus engine (nor the filetype engine etc or logged for that matter).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be great if the dropbox client could accept the CA list available for the client (or for that matter manually include the CA as a trusted CA you use for decryption) - what does Dropbox say when you contact them regarding this issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Jun 2013 17:44:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4302#M3184</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-06-02T17:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Current situation with Dropbox?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4303#M3185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command need to verify if the cert have been excluded:&lt;/P&gt;&lt;P&gt;show system setting ssl-decrypt exclude-cache&lt;/P&gt;&lt;P&gt;with reason:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; App_unsupported&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cert_Unsupported&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSL_Unsupported&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0in; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0in; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0in; font-size: 10pt; line-height: 1.5em;"&gt;Refer to this docs can help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; =&amp;gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1423"&gt;https://live.paloaltonetworks.com/docs/DOC-1423&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 09:37:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4303#M3185</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-06-03T09:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Current situation with Dropbox?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4304#M3186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys. However, my questions remain. If Dropbox client can not be decrypted, what is the proper way of excluding it? See my opening post. It used to be on the internal exclude-list but that doesn't seem to be true anymore. Why was it removed? How do you exclude it properly?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 06:47:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4304#M3186</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-06-04T06:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: Current situation with Dropbox?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4305#M3187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all, is it just the dropbox client you want to bypass or anything that has to do with dropbox?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because if its the later then you can do this exclude in the GUI where you setup the decrypt rules (dont ssl terminate for *.dropbox.com). Also look in the logs if dropbox is using some other domains today.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 08:42:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-situation-with-dropbox/m-p/4305#M3187</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-06-04T08:42:46Z</dc:date>
    </item>
  </channel>
</rss>

