<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ssl decryption best practices? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-best-practices/m-p/48478#M35684</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cases where SSL decrypt may cause issues: &lt;BR /&gt; &lt;BR /&gt;The example in "Dual ISP Branch Office Configuration" does not work well together with SSl decrypt.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Applications outside the&amp;nbsp; web browser may not read trusted CA's the same way as your web browser.&lt;BR /&gt;Bloomberg is one example.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;BlackBerry&amp;nbsp; /BES&amp;nbsp; server may also require additional configuration steps.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you use the web categories from Brightcloud in your SSL Decrypt rules and your users go to a lot of non-US web sites, &lt;/P&gt;&lt;P&gt;expect to get to know BrightClods "Suggest a new category".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Paul M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Oct 2010 08:28:33 GMT</pubDate>
    <dc:creator>pnotpub</dc:creator>
    <dc:date>2010-10-20T08:28:33Z</dc:date>
    <item>
      <title>ssl decryption best practices?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-best-practices/m-p/48475#M35681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd like to look at implementing it but I'm wary of all the potential caveats i.e. applications that don't play nice, and machines that are non-windows or non-domain so wouldn't get a trusted CA via Group Policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've read the guides so know how to do it and what the suggested categories are to exclude, but I'd be grateful for any real-world feedback from those of you who have done this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you have custom URL categories and have a site in one of those, which takes preference in the SSL decryption rules i.e. if www.domain.com is in both "auctions" and "corp whitelist" and a decryption policy is defined to exclude "auctions" what happens?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Oct 2010 20:01:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-best-practices/m-p/48475#M35681</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-10-15T20:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: ssl decryption best practices?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-best-practices/m-p/48476#M35682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The categories decrypted would depend on your local preference. As far as the example with the &lt;A href="http://www.domain.com"&gt;www.domain.com&lt;/A&gt;, it would depend on the orfer of the rule. Rules are looked at from top to bottom. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 23:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-best-practices/m-p/48476#M35682</guid>
      <dc:creator>ggutierrez</dc:creator>
      <dc:date>2010-10-18T23:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: ssl decryption best practices?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-best-practices/m-p/48477#M35683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but that isn't really what I was getting at.&amp;nbsp; I wondered from other peoples experimentation if there were any "definitely don't try and decrypt XYZ" scenarios.&amp;nbsp; For example I read about Microsoft Update not working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Oct 2010 17:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-best-practices/m-p/48477#M35683</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-10-19T17:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: ssl decryption best practices?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-best-practices/m-p/48478#M35684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cases where SSL decrypt may cause issues: &lt;BR /&gt; &lt;BR /&gt;The example in "Dual ISP Branch Office Configuration" does not work well together with SSl decrypt.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Applications outside the&amp;nbsp; web browser may not read trusted CA's the same way as your web browser.&lt;BR /&gt;Bloomberg is one example.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;BlackBerry&amp;nbsp; /BES&amp;nbsp; server may also require additional configuration steps.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you use the web categories from Brightcloud in your SSL Decrypt rules and your users go to a lot of non-US web sites, &lt;/P&gt;&lt;P&gt;expect to get to know BrightClods "Suggest a new category".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Paul M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 08:28:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-best-practices/m-p/48478#M35684</guid>
      <dc:creator>pnotpub</dc:creator>
      <dc:date>2010-10-20T08:28:33Z</dc:date>
    </item>
  </channel>
</rss>

