<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User based ssl decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91607#M43651</link>
    <description>&lt;P&gt;Sorry that was used in policy so that's also ok.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jun 2016 11:31:58 GMT</pubDate>
    <dc:creator>ToniE</dc:creator>
    <dc:date>2016-06-23T11:31:58Z</dc:date>
    <item>
      <title>User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90832#M43600</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try to test ssl forward proxy decryption. It works fine if I use IP address as a source but if I use Users(domain) as a source it doesn't work. I can't use IP's for testing because our IP's floating. What I need to check in configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Toni&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 08:18:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90832#M43600</guid>
      <dc:creator>ToniE</dc:creator>
      <dc:date>2016-06-22T08:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90850#M43601</link>
      <description>&lt;P&gt;Is user identified properly and does show up on &lt;EM&gt;#show user ip-user-mapping all&lt;/EM&gt;?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 08:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90850#M43601</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2016-06-22T08:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90880#M43604</link>
      <description>&lt;P&gt;please take a look through this article to make sure UserID is set up properly:&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-User-ID/ta-p/69321" target="_blank"&gt;Getting Started: User-ID&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 09:33:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90880#M43604</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-06-22T09:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90881#M43605</link>
      <description>&lt;P&gt;Yep. User-ID works fine but user based decryption not.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 09:44:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90881#M43605</guid>
      <dc:creator>ToniE</dc:creator>
      <dc:date>2016-06-22T09:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90950#M43615</link>
      <description>&lt;P&gt;That's odd.&amp;nbsp; We've been using TLS decryption for quite a while based on Active Directory group membership.&amp;nbsp; It works fine here (other than the fact that downloads over decrypted TLS sessions are incredibly slow).&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 12:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90950#M43615</guid>
      <dc:creator>scottsander</dc:creator>
      <dc:date>2016-06-22T12:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90960#M43619</link>
      <description>&lt;P&gt;Thanks for information. At least I know now that it could work.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 12:33:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/90960#M43619</guid>
      <dc:creator>ToniE</dc:creator>
      <dc:date>2016-06-22T12:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91065#M43627</link>
      <description>&lt;P&gt;Which version of PANOS are you running on?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 14:07:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91065#M43627</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2016-06-22T14:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91114#M43632</link>
      <description>&lt;P&gt;I am running 7.0.5-h2, use user ID and do user based decryption as part of a pilot for decryption right now. No issues here.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 14:54:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91114#M43632</guid>
      <dc:creator>googol</dc:creator>
      <dc:date>2016-06-22T14:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91445#M43641</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our current version is 7.0.5-h2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How you configure policy. Source address any and user&amp;nbsp;domain\user ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;br&lt;/P&gt;&lt;P&gt;Toni&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 07:25:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91445#M43641</guid>
      <dc:creator>ToniE</dc:creator>
      <dc:date>2016-06-23T07:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91600#M43648</link>
      <description>&lt;P&gt;It seems the user to group mapping is not happening correctly. See this command for one ip&lt;/P&gt;&lt;P&gt;show user ip-user-mapping ip x.x.x.x&lt;/P&gt;&lt;P&gt;See if user is showing correctly&lt;/P&gt;&lt;P&gt;See also associated groups are showing correctly&lt;/P&gt;&lt;P&gt;If not add group mapping under Device-&amp;gt; user identification-&amp;gt; group mapping&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 10:35:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91600#M43648</guid>
      <dc:creator>Roby_Sreejith</dc:creator>
      <dc:date>2016-06-23T10:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91602#M43650</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user ip-user-mapping ip x.x.x.x&amp;nbsp; --&amp;gt; I can see my username correctly. But I can't see any groups associated&amp;nbsp; --&amp;gt; Groups that the user belongs to (used in policy). This is empty.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see my username in group if&amp;nbsp; --&amp;gt; show user group name "CN=XXXXXXXXX,OU=XXXXXXXX,OU=XXXX,DC=XX,DC=XXXXXX,DC=XXXX,DC=XXX"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Toni&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 10:59:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91602#M43650</guid>
      <dc:creator>ToniE</dc:creator>
      <dc:date>2016-06-23T10:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91607#M43651</link>
      <description>&lt;P&gt;Sorry that was used in policy so that's also ok.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 11:31:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91607#M43651</guid>
      <dc:creator>ToniE</dc:creator>
      <dc:date>2016-06-23T11:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: User based ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91608#M43652</link>
      <description>&lt;P&gt;Hello, I just found solution. It was in group mapping settings. User Domain was missing above Group Objects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all for help. You put me to right direction!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;br&lt;/P&gt;&lt;P&gt;Toni&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 11:36:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-based-ssl-decryption/m-p/91608#M43652</guid>
      <dc:creator>ToniE</dc:creator>
      <dc:date>2016-06-23T11:36:23Z</dc:date>
    </item>
  </channel>
</rss>

