<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Facebook IOS App and Decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-ios-app-and-decryption/m-p/79213#M43208</link>
    <description>&lt;P&gt;Thanks for the response.&amp;nbsp; That is what I thought.&amp;nbsp; So let me pose another question.&amp;nbsp; Is there a way to identify and IOS device and enforce a decryption policy based on if it is an IOS device or not?&amp;nbsp; Then maybe I would set it to decrypt if it was a Windows device and not decrypt if it was an IOS device.&lt;/P&gt;
&lt;P&gt;-Steve&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jun 2016 18:40:37 GMT</pubDate>
    <dc:creator>Steve27596</dc:creator>
    <dc:date>2016-06-06T18:40:37Z</dc:date>
    <item>
      <title>Facebook IOS App and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-ios-app-and-decryption/m-p/79089#M43146</link>
      <description>&lt;P&gt;I have been testing decryption and different apps on our iPads.&amp;nbsp;With decryption turned on we are not able to use different apps, for example Facebook.&amp;nbsp; Now if I use a browser and go to Facebook, I am fine.&amp;nbsp; Anybody do any testing with decrypting the iPad or iPhone traffic and getting Facebook to work?&lt;/P&gt;
&lt;P&gt;I am hoping that once I figure out how to get that app working, I can resolve other app issues.&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; Steve&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2016 20:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-ios-app-and-decryption/m-p/79089#M43146</guid>
      <dc:creator>Steve27596</dc:creator>
      <dc:date>2016-06-03T20:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook IOS App and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-ios-app-and-decryption/m-p/79091#M43147</link>
      <description>&lt;P&gt;Facebook has designed their iOS app to be incompatible with SSL Decryption technologies. &amp;nbsp;For iOS devices, your choices are going to be permit/deny.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you leave the decryption policy in-place, that will prevent the iOS app from working. &amp;nbsp;I believe you'll still be able to access Facebook via the mobile Safari web-browser. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2016 21:11:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-ios-app-and-decryption/m-p/79091#M43147</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2016-06-03T21:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook IOS App and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-ios-app-and-decryption/m-p/79213#M43208</link>
      <description>&lt;P&gt;Thanks for the response.&amp;nbsp; That is what I thought.&amp;nbsp; So let me pose another question.&amp;nbsp; Is there a way to identify and IOS device and enforce a decryption policy based on if it is an IOS device or not?&amp;nbsp; Then maybe I would set it to decrypt if it was a Windows device and not decrypt if it was an IOS device.&lt;/P&gt;
&lt;P&gt;-Steve&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 18:40:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-ios-app-and-decryption/m-p/79213#M43208</guid>
      <dc:creator>Steve27596</dc:creator>
      <dc:date>2016-06-06T18:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Facebook IOS App and Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/facebook-ios-app-and-decryption/m-p/79330#M43242</link>
      <description>&lt;P&gt;You can vary decryption policies by:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Source/Destination Zone&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Source/Destination Address&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Source User&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Service(port#)&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;URL Category&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you wanted to only decrypt facebook for non-iOS devices, then you'd need some sort of mechanism that separates the iOS devices from everything else. &amp;nbsp;This isn't a comprehensive list, but hopefully gives you some ideas on how you could do this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DHCP serves iOS devices 1 scope, all other devices a 2nd scope:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://serverfault.com/questions/584697/have-dhcp-use-different-scopes-based-on-mac-address-using-server-2012" target="_blank"&gt;http://serverfault.com/questions/584697/have-dhcp-use-different-scopes-based-on-mac-address-using-server-2012&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;(this article talks about doing this for VoIP phones, but should be just as applicable for iOS devices)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Leverage your wireless system to allocate device types to different VLANs. &amp;nbsp;Your wireless controller might be able to determine the host OS and place in a different VLAN (which maps to a different IP address range). &amp;nbsp;A BYOD solution could do similar things. &amp;nbsp;At an extremely "manual" level, you could make 2 SSID's, one for mobile devices, and one for everything else. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There may also be ways to identify the IP Addresses of the mobile devices, publish those addresses into an object group on the firewall via an API, and then create decryption policies based on the dynamic object groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you can "group" all of the iOS devices together, then you can give them different policies. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Again, not a conclusive list, but hopefully gives you some food for thought. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 22:31:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/facebook-ios-app-and-decryption/m-p/79330#M43242</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2016-06-07T22:31:04Z</dc:date>
    </item>
  </channel>
</rss>

