<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/68413#M39909</link>
    <description>&lt;P&gt;Depends also for which clients you are intercepting and for which purpose.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A more strict policy is that stuff that cannot be intercepted (or is not allowed to) will be blocked (meaning you cant visit that financial site from your workstation at work as an example).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you must know which sites you are "bypassing" SSL-termination for and URL-category isnt enough then create a custom URL-category where you put in your "whitelisted" sites into.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will take some time and effort but at the same time - how many financial sites (that is truly financial sites - not just forums where the topic is financial related) does your clients visit? And how many new lets say banks to there show up which you then need to whitelist?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess you might have some work the first few days but then it will level out...&lt;/P&gt;</description>
    <pubDate>Fri, 20 Nov 2015 14:48:15 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2015-11-20T14:48:15Z</dc:date>
    <item>
      <title>SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/68405#M39904</link>
      <description>&lt;P&gt;With SSL Decryption it is recomended that &lt;SPAN class="_Tgc"&gt;Financial services&lt;/SPAN&gt; &amp;amp; Medical &lt;SPAN class="_Tgc"&gt;category &lt;/SPAN&gt;is not decrypted.&lt;/P&gt;
&lt;P&gt;My question is how do you ensure that sites that should not be decrypted are not i.e. JP Morgan is clearly a &lt;SPAN class="_Tgc"&gt;Financial services&lt;/SPAN&gt; and will not get decrypted.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if a user were to access a very obsecure &lt;SPAN class="_Tgc"&gt;Financial &lt;/SPAN&gt;Website it may be classified incorrectley as such would get decrypted, the user would not know this is happneing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any logs in the PA that one can look at get see this type of mis-clasification.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2015 09:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/68405#M39904</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2015-11-20T09:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/68412#M39908</link>
      <description>&lt;P&gt;Short answer...No.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only way you're gonna know is if you know the site and submit it for re-categorization.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The rationale for not intercepting finanicial is 2-fold. &amp;nbsp;The first being PII reasons. &amp;nbsp;The second being usually these types of sites more often than not are more prone to not working when intercepted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're intercepting a site like this and users are expereincing problems you'll know and will have the chance to re-categorize it.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2015 14:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/68412#M39908</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-11-20T14:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/68413#M39909</link>
      <description>&lt;P&gt;Depends also for which clients you are intercepting and for which purpose.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A more strict policy is that stuff that cannot be intercepted (or is not allowed to) will be blocked (meaning you cant visit that financial site from your workstation at work as an example).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you must know which sites you are "bypassing" SSL-termination for and URL-category isnt enough then create a custom URL-category where you put in your "whitelisted" sites into.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will take some time and effort but at the same time - how many financial sites (that is truly financial sites - not just forums where the topic is financial related) does your clients visit? And how many new lets say banks to there show up which you then need to whitelist?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess you might have some work the first few days but then it will level out...&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2015 14:48:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/68413#M39909</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2015-11-20T14:48:15Z</dc:date>
    </item>
  </channel>
</rss>

