<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No Block Page when accessing Blocked Categories over HTTPS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154540#M50900</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I have recently noticed that when I test access to URLs of blocked categories over HTTPS, I do not get a 'Blocked Page' display from the Palo. It just says the Page Cannot be Displayed and show the connection was reset.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The URL filtering log correctly show as 'Block-URL' for the action. I just do not get a 'Block Page'.&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSL decrypt is not configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I get a block page for blocked categories over HTTPS, without SSL Decrypt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your assistance is appreciated&lt;/P&gt;</description>
    <pubDate>Fri, 28 Apr 2017 15:30:11 GMT</pubDate>
    <dc:creator>Bocsa</dc:creator>
    <dc:date>2017-04-28T15:30:11Z</dc:date>
    <item>
      <title>No Block Page when accessing Blocked Categories over HTTPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154540#M50900</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I have recently noticed that when I test access to URLs of blocked categories over HTTPS, I do not get a 'Blocked Page' display from the Palo. It just says the Page Cannot be Displayed and show the connection was reset.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The URL filtering log correctly show as 'Block-URL' for the action. I just do not get a 'Block Page'.&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSL decrypt is not configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I get a block page for blocked categories over HTTPS, without SSL Decrypt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your assistance is appreciated&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 15:30:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154540#M50900</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2017-04-28T15:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: No Block Page when accessing Blocked Categories over HTTPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154552#M50901</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/8460"&gt;@Bocsa&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you looking for this ?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Serve-a-URL-Response-Page-Over-an-HTTPS-Session-Without/ta-p/55998" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Serve-a-URL-Response-Page-Over-an-HTTPS-Session-Without/ta-p/55998&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;-Kiwi&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 15:57:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154552#M50901</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-04-28T15:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: No Block Page when accessing Blocked Categories over HTTPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154557#M50902</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I had tried this earlier. It doesn't solve the problem. In my case all it did was give me a message saying 'The Connection to the Site is Not Trusted' (ie the standard message you get when accessing an SSL site without a Trusted Certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still do not get a 'Block Page'&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 16:31:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154557#M50902</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2017-04-28T16:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: No Block Page when accessing Blocked Categories over HTTPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154560#M50904</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/8460"&gt;@Bocsa&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The security warning could have been a few things:&lt;/P&gt;&lt;P&gt;1) The Forward Trust certificate wan't trusted by the client, this cert actually needs to be imported and trusted by the clients.&lt;/P&gt;&lt;P&gt;2) The site you were attempting to visit wasn't a trusted certificate, so it served the Forward Untrust cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You also need to enable the ability to inject the response pages within an HTTPS session which could also be the issue. Are you sure that you ran the '&lt;EM&gt;set deviceconfig settting ssl-decrypt url-proxy yes'&lt;/EM&gt;&amp;nbsp; command, without this setting then the device won't inject the response pages.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 16:49:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154560#M50904</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-04-28T16:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: No Block Page when accessing Blocked Categories over HTTPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154958#M50989</link>
      <description>&lt;P&gt;&lt;SPAN&gt;''&lt;EM&gt;You also need to enable the ability to inject the response pages within an HTTPS session which could also be the issue&lt;/EM&gt;''.....I'm not sure of what you mean by enable to ability to inject the response pages here. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, I have put in the command '&lt;EM&gt;set deviceconfig settting ssl-decrypt url-proxy yes'&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 08:53:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/154958#M50989</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2017-05-03T08:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: No Block Page when accessing Blocked Categories over HTTPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/155077#M51018</link>
      <description>&lt;P&gt;&lt;SPAN&gt;If the sites cert isn't supported by the TSL, thats happening before the request can be blocked. Test if you get it with a site that has a supported cert, but is set to be blocked.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 21:18:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/155077#M51018</guid>
      <dc:creator>ChrisRussell</dc:creator>
      <dc:date>2017-05-03T21:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: No Block Page when accessing Blocked Categories over HTTPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/155103#M51023</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem you are having is based on the fact that the only FW can in normal cercomstances can not highjack the ssl session because it does not have the root cert of the destination. therefore it can only work if you do a man in the middle (or ssl inspection as it is called in the firewall). this will terminate the session of the client on the firewall witch in turn wil present it's own cert, this cert wil be signed by the firewall itself unless you have taken precautions and installed a trusted public ca. In this case it presents it's a cert signed by itself, which is not trusted by the client, thats why you're getting a site not trusted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this kind of explains the problem.&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 06:50:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-block-page-when-accessing-blocked-categories-over-https/m-p/155103#M51023</guid>
      <dc:creator>P.Braat</dc:creator>
      <dc:date>2017-05-08T06:50:35Z</dc:date>
    </item>
  </channel>
</rss>

