<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't access dropbox website .PAN does SSL inspection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163269#M52875</link>
    <description>&lt;P&gt;If William's post doesnt work, I would highly recommend using the dev tools in Chome which can let you know what resources arent getting through. &amp;nbsp;We recently opened up Box and there were some backend CDNs that we had to whitelist to get it to work. &amp;nbsp;Sometimes there are some JS files running on a CDN where if they dont load it hangs the page, which might be your issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Worst comes to worst,&amp;nbsp;looking at a packet capture on both your local system and on the Palo to see if packets are being sent out of order or if things are getting caught up.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jun 2017 17:33:57 GMT</pubDate>
    <dc:creator>it-thomas</dc:creator>
    <dc:date>2017-06-26T17:33:57Z</dc:date>
    <item>
      <title>Can't access dropbox website .PAN does SSL inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163098#M52837</link>
      <description>&lt;P&gt;Traffic traverse&amp;nbsp; as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PC(attempting to access dropbox website &amp;gt;Web proxy that does ssl inspection&amp;gt;palo alto&amp;nbsp; firewall that does ssl inspection and forward drop box traffic to&amp;gt;web proxy that does ssl inspection&amp;gt; drop box website.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Symptom: I get dropbox home page but it just hangs at home page and I can't go any further&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dropbox access works when I disable ssl inspection on palo alto firewall..&lt;/P&gt;&lt;P&gt;Can someone please help and advice What changes might be needed on my PAN firewall to get things working&lt;/P&gt;&lt;P&gt;Where exactly on panw I should be looking at&amp;nbsp; and what logging on panw firewall can help me identfy what is going on here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note:&lt;/P&gt;&lt;P&gt;1)SSL inspection is a must on my proxy and firewall&lt;/P&gt;&lt;P&gt;2)I am not worried about ssl pinned dropbox thick client but need access to dropbox website&lt;/P&gt;&lt;P&gt;3)Other https website I tested just works fine!!&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2017 16:52:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163098#M52837</guid>
      <dc:creator>dropboxintegration</dc:creator>
      <dc:date>2017-06-24T16:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access dropbox website .PAN does SSL inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163105#M52838</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67476"&gt;@dropboxintegration&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which dropbox App-ID signature are you using in your security rule? Also, which URL Category do you have configured in your SSL inspection rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2017 18:17:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163105#M52838</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-24T18:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access dropbox website .PAN does SSL inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163119#M52842</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67476"&gt;@dropboxintegration&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition to &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt;'s questions, what url categories do you allow? Because dropbox also loads some third party content when you open the website (&amp;nbsp;&lt;A href="https://urlscan.io/result/708a0d7a-6695-4d13-8618-c078dc4d7f94#summary" target="_blank"&gt;https://urlscan.io/result/708a0d7a-6695-4d13-8618-c078dc4d7f94#summary&lt;/A&gt; ). It could be if some additional ressources are blocked that the site does nor work properly. (I see a similar behaviour when I connect to dropbox with local adblockers enabled).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: Do you really decrypt-encrypt-decrypt-encrypt-decrypt-encrypt (3 times tls decryption) all the encrypted sessions?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2017 19:55:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163119#M52842</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-24T19:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access dropbox website .PAN does SSL inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163150#M52852</link>
      <description>&lt;P&gt;Thanks @ Willian @1vsys_remo!&lt;BR /&gt;Good question&lt;BR /&gt;&amp;nbsp;Which dropbox App-ID signature are you using in your security rule?&lt;BR /&gt;&amp;gt;I am on proxy side and do not have access to PAN so checking with firewall admins and will post.Is there a specific App-id signature we should be using in PAN for dropbox policy.Looks like PAN OS maintain a list of application in default no-decrypt list and dropbox isn't there in the list.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/List-of-Applications-Excluded-from-SSL-Decryption/ta-p/62201" target="_self"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/List-of-Applications-Excluded-from-SSL-Decryption/ta-p/62201&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Are there any special setup required on PAN when we&amp;nbsp; decrypt dropbox app.&lt;BR /&gt;Can dropbox app reliably work when pan decrypt traffic(my proxy can perfectly crack browser based dropbox- exception is ssl pinned dropbox thick client which is expected)&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Also, which URL Category do you have configured in your SSL inspection rule?&lt;BR /&gt;&amp;gt; not sure .I think there is custom&amp;nbsp; URL category configured on PAN with decryption policy that include the domain&amp;nbsp; *.dropbox.com&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;@1vsys_remo&lt;BR /&gt;Do you really decrypt-encrypt-decrypt-encrypt-decrypt-encrypt (3 times tls decryption) all the encrypted sessions?&lt;BR /&gt;No we don't for all encrypted traffic but dropbox has to go through this:)..&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2017 16:24:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163150#M52852</guid>
      <dc:creator>dropboxintegration</dc:creator>
      <dc:date>2017-06-25T16:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access dropbox website .PAN does SSL inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163154#M52853</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67476"&gt;@dropboxintegration&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Below&amp;nbsp;is an example of the security policy and decryption policy I have running on my lab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In terms of the URL filtering, you can use either approach.&lt;/P&gt;&lt;P&gt;1. You can allow or alert on the &lt;STRONG&gt;online-&lt;/STRONG&gt;s&lt;STRONG&gt;torage-and-backup &lt;/STRONG&gt;category; however, if you have tight restrictions on users accessing online storage websites, then the next option is the most viable.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;2. You can include the wildcard *.dropbox.com into the "Allow List" in the URL filtering profile.&amp;nbsp;With this configuration, even if the&amp;nbsp;&lt;STRONG&gt;online-&lt;/STRONG&gt;&lt;SPAN&gt;s&lt;/SPAN&gt;&lt;STRONG&gt;torage-and-backup &lt;/STRONG&gt;category is blocked, the&lt;STRONG&gt; Allow list &lt;/STRONG&gt;is&amp;nbsp;evaluated&amp;nbsp;before the other categories.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. The third option is the one you mentioned where, you can create a custom URL filtering category, by basicaly doing the same thing as option 2 and specifying the dropbox wildcard domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my example below, I am allowing the entire category, but just because it is a Lab. As for the App-ID I am allowing the entire dropbox App-ID tree. Remember, that firewall has different sub-applications serving different purposes. Dropbox App-ID is the parent application, hence everything else under that will be allowed in this policy.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security Policy:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2017-06-25 at 10.32.14 AM.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9926i608A6827729AEBB2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2017-06-25 at 10.32.14 AM.png" alt="Screen Shot 2017-06-25 at 10.32.14 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;In my decryption policy, I am also keeping it simple, and decrypting everything except for Financial and health care.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Decryption Policy&lt;/STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2017-06-25 at 10.33.35 AM.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9927iAC332C269154D988/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2017-06-25 at 10.33.35 AM.png" alt="Screen Shot 2017-06-25 at 10.33.35 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2017 17:47:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163154#M52853</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-25T17:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access dropbox website .PAN does SSL inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163269#M52875</link>
      <description>&lt;P&gt;If William's post doesnt work, I would highly recommend using the dev tools in Chome which can let you know what resources arent getting through. &amp;nbsp;We recently opened up Box and there were some backend CDNs that we had to whitelist to get it to work. &amp;nbsp;Sometimes there are some JS files running on a CDN where if they dont load it hangs the page, which might be your issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Worst comes to worst,&amp;nbsp;looking at a packet capture on both your local system and on the Palo to see if packets are being sent out of order or if things are getting caught up.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2017 17:33:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163269#M52875</guid>
      <dc:creator>it-thomas</dc:creator>
      <dc:date>2017-06-26T17:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access dropbox website .PAN does SSL inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163280#M52876</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;Willian and ithomas@lb.com!!&lt;/P&gt;&lt;P&gt;We narrowed down the issue to specific version of IE 11.0.9600 that seems to be messing up dropbox traffic. This works fine with chrome!&lt;BR /&gt;May be the har capture from IE or tcpdump&amp;nbsp;from local system would&amp;nbsp;give us some clue why it’s failing.. Any thoughts?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2017 18:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163280#M52876</guid>
      <dc:creator>dropboxintegration</dc:creator>
      <dc:date>2017-06-26T18:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access dropbox website .PAN does SSL inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163478#M52921</link>
      <description>&lt;P&gt;Moving to Chrome does seem to fix a lot of issues, which would make me think that its an issue with the browser and not your network gear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With Internet Exploder open, hit F12. &amp;nbsp;In that window bring up the Console tab. &amp;nbsp;From there you can load the dropbox page and it should let you know the errors that are happening on the back end. &amp;nbsp;It is possible that a JS file is getting blocked that is specific to IE, or in the event of it auto forwarding, that the HTTP 302 is getting lost somewhere due to being decrypted multiple times.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One way to test would be to bypass decrpytion on one appliance for that website (or a username if possible), see if it resolves the issue, if not disable decrypt&amp;nbsp;the other appliance, see if that resolves. &amp;nbsp;If neither of those resolve the issue, disable on both devices and see if the issue resolves itself. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2017 17:57:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-dropbox-website-pan-does-ssl-inspection/m-p/163478#M52921</guid>
      <dc:creator>it-thomas</dc:creator>
      <dc:date>2017-06-27T17:57:26Z</dc:date>
    </item>
  </channel>
</rss>

