<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is Decryption needed without URL filtering? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-decryption-needed-without-url-filtering/m-p/149955#M49855</link>
    <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currenly have a Palo-5050 v7.18 doing firewalling and URL filtering.&lt;/P&gt;&lt;P&gt;We have SSL decryption enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because Palo does not support transparent authentication using Chromebooks and because we do not like the Palo URL reporting, we are looking at getting rid of the URL filtering part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we still need to have SSL decryption enabled for normal firewall apps and function?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If yes, does that mean we would need to have multiple SSL certs installed on our client devices:&lt;/P&gt;&lt;P&gt;1 for Palo SSL decyption&lt;/P&gt;&lt;P&gt;1 for new URL filtering product&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much thanks.&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2017 16:04:37 GMT</pubDate>
    <dc:creator>dannon</dc:creator>
    <dc:date>2017-03-28T16:04:37Z</dc:date>
    <item>
      <title>Is Decryption needed without URL filtering?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-decryption-needed-without-url-filtering/m-p/149955#M49855</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currenly have a Palo-5050 v7.18 doing firewalling and URL filtering.&lt;/P&gt;&lt;P&gt;We have SSL decryption enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because Palo does not support transparent authentication using Chromebooks and because we do not like the Palo URL reporting, we are looking at getting rid of the URL filtering part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we still need to have SSL decryption enabled for normal firewall apps and function?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If yes, does that mean we would need to have multiple SSL certs installed on our client devices:&lt;/P&gt;&lt;P&gt;1 for Palo SSL decyption&lt;/P&gt;&lt;P&gt;1 for new URL filtering product&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much thanks.&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 16:04:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-decryption-needed-without-url-filtering/m-p/149955#M49855</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2017-03-28T16:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is Decryption needed without URL filtering?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-decryption-needed-without-url-filtering/m-p/149988#M49861</link>
      <description>&lt;P&gt;Depends on the application you are trying to catch and the need to see threats, short answer is yes you want to decrypt the traffic more than likely so leave that on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your new URL filtering product requires SSL decrytion then it will need this as well. I imagine that in a school enviroment you are probably looking at something like a Barracuda, in which case it helps to have SSL decryption enabled and you would need the required certs to configure this correctly loaded onto the client devices.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 18:30:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-decryption-needed-without-url-filtering/m-p/149988#M49861</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-28T18:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Is Decryption needed without URL filtering?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-decryption-needed-without-url-filtering/m-p/150234#M49911</link>
      <description>&lt;P&gt;Hi Dannon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Decryption would be better for application and threat detection. If not, we might not see the application shift which may happen after the base application is read. Decryption requires a certificate which is marked as CA and the private key should be on the firewall. You could have 2 different certificates for Palo Alto, URL filtering service. However, you could also export certificate from one device and import it into another (PA can do that, not sure about the other device).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 19:33:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-decryption-needed-without-url-filtering/m-p/150234#M49911</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-03-29T19:33:55Z</dc:date>
    </item>
  </channel>
</rss>

