<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/75145#M41886</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have recentley tuned on SSL Decryption for some users.&lt;/P&gt;
&lt;P&gt;Since then we are getting some SSL sites that cannot be accessed due to cypher mismatch. It is something we were exepcting, but not the amount of URL this is happneing for.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question, is there a setting that I can turn on that will allow the site to be accessed if the SSL Decryption fails ?&lt;/P&gt;
&lt;P&gt;My assumption is that most sites will get decrypted and we will get the relevant APP-id data from it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Mar 2016 10:11:24 GMT</pubDate>
    <dc:creator>RC-BHF</dc:creator>
    <dc:date>2016-03-24T10:11:24Z</dc:date>
    <item>
      <title>SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/75145#M41886</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have recentley tuned on SSL Decryption for some users.&lt;/P&gt;
&lt;P&gt;Since then we are getting some SSL sites that cannot be accessed due to cypher mismatch. It is something we were exepcting, but not the amount of URL this is happneing for.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question, is there a setting that I can turn on that will allow the site to be accessed if the SSL Decryption fails ?&lt;/P&gt;
&lt;P&gt;My assumption is that most sites will get decrypted and we will get the relevant APP-id data from it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 10:11:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/75145#M41886</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2016-03-24T10:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/75146#M41887</link>
      <description>&lt;P&gt;You can decide what you want to do with sites that can't be decrypted in SSL forward proxy options in decryption profile:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Unsupported Mode Checks

Block sessions with unsupported versions

Block sessions with unsupported cipher suites

Block sessions with client authentication&lt;/PRE&gt;</description>
      <pubDate>Thu, 24 Mar 2016 10:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/75146#M41887</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-03-24T10:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/75163#M41890</link>
      <description>&lt;P&gt;On the more recent PAN-OS versions, if a site is using an unsupported cipher then it is added automatically to the ssl-decrypt exclude cache and will no longer be decrypted :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/SSL-decrypt-exclude-cache-and-unsupported-ECDHE-cipher-suites/ta-p/68109" target="_blank"&gt;SSL-decrypt-exclude-cache-and-unsupported-cipher-suites&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 13:35:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption/m-p/75163#M41890</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-03-24T13:35:22Z</dc:date>
    </item>
  </channel>
</rss>

