<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Force Safe Search without SSL decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160790#M52389</link>
    <description>&lt;P&gt;Hi Willian,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I might be wrong, but I don't see us implementing SSL decryption anytime soon, due to a number of factors. &amp;nbsp; Could you please elaborate a little, when you say that in your experience DNS-Proxy route is not going to&amp;nbsp;resolve this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are not looking for a fool-proof solution at this time, more like at having something in place, rather than nothing.&lt;/P&gt;&lt;P&gt;Did you find user were able to circumvent this easily, or it just plain didn't work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luca&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jun 2017 18:30:30 GMT</pubDate>
    <dc:creator>LucaMarchiori</dc:creator>
    <dc:date>2017-06-12T18:30:30Z</dc:date>
    <item>
      <title>Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160766#M52383</link>
      <description>&lt;P&gt;We are a K-12 school district. &amp;nbsp;SSL decryption is not in the cards, at least for the time being. &amp;nbsp;From what I read, enabling safe search enforcement in URL filtering profile will not work properly without having implemented SSL decryption&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that's correct, is a DNS proxy the way to go, as described here:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.google.com/websearch/answer/186669?hl=en" target="_blank"&gt;https://support.google.com/websearch/answer/186669?hl=en&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 16:32:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160766#M52383</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-12T16:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160786#M52386</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28602"&gt;@LucaMarchiori&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Because most search engines encrypt their search results, you must enable SSL forward proxy decryption so that the firewall can inspect the search traffic and detect the safe search settings.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/60/pan-os/newfeaturesguide/content-inspection-features/url-filtering-safe-search-enforcement" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/60/pan-os/newfeaturesguide/content-inspection-features/url-filtering-safe-search-enforcement&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/url-filtering/safe-search-enforcement.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/url-filtering/safe-search-enforcement.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://researchcenter.paloaltonetworks.com/2015/01/firewall-pro-tip-enforce-safe-search-without-blocking-search-results/" target="_blank"&gt;https://researchcenter.paloaltonetworks.com/2015/01/firewall-pro-tip-enforce-safe-search-without-blocking-search-results/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think DNS Proxy will resolve this challenge for you, at least not based on my own experience.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 17:16:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160786#M52386</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-12T17:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160790#M52389</link>
      <description>&lt;P&gt;Hi Willian,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I might be wrong, but I don't see us implementing SSL decryption anytime soon, due to a number of factors. &amp;nbsp; Could you please elaborate a little, when you say that in your experience DNS-Proxy route is not going to&amp;nbsp;resolve this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are not looking for a fool-proof solution at this time, more like at having something in place, rather than nothing.&lt;/P&gt;&lt;P&gt;Did you find user were able to circumvent this easily, or it just plain didn't work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luca&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 18:30:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160790#M52389</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-12T18:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160809#M52393</link>
      <description>&lt;P&gt;What are you trying to protect from in your K-12 network?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 21:26:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160809#M52393</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-06-12T21:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160811#M52395</link>
      <description>&lt;P&gt;In short, we are trying to avoid kids getting inappropriate results from google search. &amp;nbsp;This was sparked from one complaint at an elementary site, even though we are blocking adult categories with URL filtering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my mind this is about enforcing a browser setting, and as such should be handled on the device side (GPO, MDM, etc). &amp;nbsp;Nevertheless, I've being asked if anything&amp;nbsp;could be accomplished with our PA firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 21:38:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160811#M52395</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-12T21:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160818#M52396</link>
      <description>&lt;P&gt;So..."Content Filtering" should be able to get you what you need (URL Profiles.) &amp;nbsp;However I thought I heard not doing SSL decryption you can bypass that filtering control by using Google's translation services. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me do some searching real quick.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 21:50:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160818#M52396</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-06-12T21:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160819#M52397</link>
      <description>&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Block-Alert-Category-of-a-Website-that-is-Embedded-in-a/ta-p/62409&amp;nbsp;" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Block-Alert-Category-of-a-Website-that-is-Embedded-in-a/ta-p/62409&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 21:52:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160819#M52397</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-06-12T21:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160825#M52402</link>
      <description>&lt;P&gt;Yes, if you're unable to use SSL decryption in order to enforce safe-search and if you don't have an endpoint-specific solution (GPO/MDM), then I would recommend leveraging google's DNS-based safe-search configuration as you posted in your original question. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:10:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160825#M52402</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-06-12T22:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160828#M52404</link>
      <description>&lt;P&gt;We are already doing URL filtering for the usual inappropriate categories. &amp;nbsp;Somehow this kid managed to get explicit pics on the browser, supposedly by using search function. &amp;nbsp;Unfortunately this was reported as an anecdote, without any technical details. &amp;nbsp;I took at face value.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I click on the link you provided I get:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="lia-text error-description"&gt;An invalid set of parameters has been specified in the url.&lt;/DIV&gt;&lt;DIV class="lia-text"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Force-Safe-Search-without-SSL-decryption/m-p/160818" target="_blank"&gt;Return to my original page&lt;/A&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:14:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160828#M52404</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-12T22:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160834#M52405</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, the DNS Proxy solution &lt;EM&gt;should&lt;/EM&gt; be working OK? &amp;nbsp;I'm going to setup a test site, and see what I come up with.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:17:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160834#M52405</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-12T22:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160838#M52406</link>
      <description>&lt;P&gt;sorry it had an extra space&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Block-Alert-Category-of-a-Website-that-is-Embedded-in-a/ta-p/62409" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Block-Alert-Category-of-a-Website-that-is-Embedded-in-a/ta-p/62409&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:20:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160838#M52406</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-06-12T22:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160840#M52407</link>
      <description>&lt;P&gt;It's a good first step. &amp;nbsp;The DNS-based solution should enforce "safe search" - meaning Google will be providing filtered search results. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This would address the case where your student searched for inappropriate content via the google search engine and google was the one displaying the inappropriate content. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Students are resourceful, though - so there&amp;nbsp;will be additional steps that you need to take, such as blocking access to proxy websites,&amp;nbsp;blocking VPN applications, etc. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:23:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160840#M52407</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-06-12T22:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160841#M52408</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for fixing it. &amp;nbsp;Yes, we already have security profiles in place. &amp;nbsp;Mind you this is the first report of this nature that I've seen in a couple of years, so I'd say this is&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt; a common occurrence.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:25:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160841#M52408</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-12T22:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160843#M52409</link>
      <description>&lt;P&gt;Blocking outbound DNS from students would also need to be blocked, or else they'll just point their DNS queries to an external resolver.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without SSL decryption though, you'll be chasing this a lot. A student forced to use google safe search may decide Bing is just fine for them (or DuckDuckGo, or Yandex, or... etc.). Longer term I'd recommend looking into the decryption end. You'll get a lot better enforcement if you can trigger on every request rather than just the requests in clear text.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:28:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160843#M52409</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-06-12T22:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160844#M52410</link>
      <description>&lt;P&gt;Yes, they are resourceful, you have to admire that. &amp;nbsp;We're not seeing much in terms of VPNs at elementary sites. &amp;nbsp;It's a different story at secondary ones. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &amp;nbsp;Might just start another thread on how you guys manage to stop &lt;EM&gt;all&lt;/EM&gt; VPNs, when PA only detects unknown-tcp, unknown-udp, or ipsec-esp-udp traffic...&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:32:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160844#M52410</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-12T22:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160845#M52411</link>
      <description>&lt;P&gt;Couldn't one block the "search" category though, and allow google as an exception?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree this is not the ideal way to control this. &amp;nbsp;We are not looking for ideal, at this point.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:34:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160845#M52411</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-12T22:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160846#M52412</link>
      <description>&lt;P&gt;Personally I wonder about the extra load imposed by SSL decryption, at least on our PA-500 devices (with memory upgrade). &amp;nbsp;They are already soo slow, I'd hate to see them becoming even slower, if that is possible. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:38:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160846#M52412</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-12T22:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160847#M52413</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;gt; Couldn't one block the "search" category though, and allow google as an exception?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Probably not, because like Google the services are much more than just search. You could cover many examples, but someone logged into live.com to view their hotmail account would likely be able to do a bing search from inside their email. The user isn't on a search site, and they didn't make a new connection to bing.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'd say start with the DNS method you linked in the first post on this thread, and push for decryption as a more full solution later.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160847#M52413</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-06-12T22:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160848#M52414</link>
      <description>&lt;P&gt;so technically SSL decryption is not required to turn on SAFE SEARCH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that being said if the browser returns search results(most do) inside ssl then yes you need a decryption policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;otherwise you can enable safe search directly on the PC....GPO&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;meanwhile there are some PAN alternatives&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/url-filtering/safe-search-enforcement.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/url-filtering/safe-search-enforcement.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;another thing Ive done for K-12 is blacklist everything and then only whitelist approved sites&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if google search is approved then you need to find a control for that site&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 22:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/160848#M52414</guid>
      <dc:creator>DarinSutton</dc:creator>
      <dc:date>2017-06-12T22:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: Force Safe Search without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/161064#M52449</link>
      <description>&lt;P&gt;I've setup a DNS Proxy at one of the primary sites. &amp;nbsp;I created a bunch of static entries for google.ca, *.google.ca, etc pointing to&amp;nbsp;216.239.38.120. &amp;nbsp;As interface I assigned the proxy to the LAN interface. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I test on a windows client, after running ipconfig /flushdns, client still gets an answer from one of our internal DNS server (at the DC), not from the local PA proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN class="crayon-e"&gt;show &lt;/SPAN&gt;&lt;SPAN class="crayon-v"&gt;dns&lt;/SPAN&gt;&lt;SPAN class="crayon-o"&gt;-&lt;/SPAN&gt;&lt;SPAN class="crayon-e"&gt;proxy &lt;/SPAN&gt;&lt;SPAN class="crayon-e"&gt;statistics &lt;/SPAN&gt;&lt;SPAN class="crayon-e"&gt;all&lt;/SPAN&gt;&lt;/EM&gt; confirmed that the proxy received zero requests. &amp;nbsp;I think I'm missing something else. &amp;nbsp;Do I need to setup a proxy rule? &amp;nbsp;I thought only a DNS proxy and some static entries were needed for this to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2017 21:34:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-safe-search-without-ssl-decryption/m-p/161064#M52449</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-06-13T21:34:55Z</dc:date>
    </item>
  </channel>
</rss>

