<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Office 365 SOAP error : Session End Reason decrypt-error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/163669#M52960</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5299"&gt;@bpeeri&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is this only on this app-id or do you see the same error elsewhere. From your screenshots it looks like you could be running 8.0.*. Are you potentially running into the following bug fixed in the 8.0.3 release?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Fixed an issue on PA-3000 Series firewalls where SSL sessions failed due to memory depletion in the proxy memory pool; Traffic logs displayed the reason &lt;/SPAN&gt;decrypt-error&lt;SPAN&gt; .&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jun 2017 18:00:26 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-06-28T18:00:26Z</dc:date>
    <item>
      <title>Office 365 SOAP error : Session End Reason decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/163646#M52955</link>
      <description>&lt;P&gt;I am having issues with SSL decryption for office365 . In specific this is related to Azure API and SOAP protocol .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic to azure cloud via soap to the following URL "roaming.officeapps.live.com/rs/RoamingSoapService.svc" is keep getting "&lt;SPAN&gt;decrypt-error" .&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Trying to bypass and adding the site to the &amp;nbsp;exclude list , and/or adding it to a url profile that bypass decryption does not seems to work as decryption still occure .&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;** Decryption is a must as i need to control to which offcice365 domain we allow access, for which we use &amp;nbsp;cusom app as demonstrated in this KB : &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/FAQ-Office-365-Access-Control/ta-p/94949" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/FAQ-Office-365-Access-Control/ta-p/94949&lt;/A&gt; **&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9969i70316A294FE6DB41/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="11.jpg" alt="11.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9970i16506EB19712EF74/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="12.jpg" alt="12.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have anyone sucssfuly managed SSL decryption with office 365 SOAP Azure API ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 15:46:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/163646#M52955</guid>
      <dc:creator>bpeeri</dc:creator>
      <dc:date>2017-06-28T15:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 SOAP error : Session End Reason decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/163669#M52960</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5299"&gt;@bpeeri&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is this only on this app-id or do you see the same error elsewhere. From your screenshots it looks like you could be running 8.0.*. Are you potentially running into the following bug fixed in the 8.0.3 release?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Fixed an issue on PA-3000 Series firewalls where SSL sessions failed due to memory depletion in the proxy memory pool; Traffic logs displayed the reason &lt;/SPAN&gt;decrypt-error&lt;SPAN&gt; .&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 18:00:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/163669#M52960</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-28T18:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 SOAP error : Session End Reason decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/163672#M52961</link>
      <description>Hi. This issue has been with 8.0.2 running on VM500 and VM700 . Can you let me know what is the bug (or issue ID) on 8.0.2 ? , as i looked in the release notes for 8.0.3 but didn't see any item that seems to be the root cause of my issue .</description>
      <pubDate>Wed, 28 Jun 2017 18:12:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/163672#M52961</guid>
      <dc:creator>bpeeri</dc:creator>
      <dc:date>2017-06-28T18:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 SOAP error : Session End Reason decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/163689#M52963</link>
      <description>&lt;P&gt;Not the bug I was thinking it could be; is this all SOAP sessions or just the Office 365 sessions that are giving you the decrypt-error log?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 20:07:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/163689#M52963</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-28T20:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 SOAP error : Session End Reason decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/164947#M53112</link>
      <description>&lt;P&gt;The issue persist only with soap .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to identify that this is related to a very specific connection to office 365 .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.office.com/en-us/article/Network-requests-in-Office-365-ProPlus-and-Mobile-eb73fcd1-ca88-4d02-a74b-2dd3a9f3364d" target="_self"&gt;https://support.office.com/en-us/article/Network-requests-in-Office-365-ProPlus-and-Mobile-eb73fcd1-ca88-4d02-a74b-2dd3a9f3364d&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Required:&lt;/STRONG&gt;Roaming Services.&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Office client only | Logged on user&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;ea-roaming.officeapps.live.com&lt;/P&gt;&lt;P&gt;sea-roaming.officeapps.live.com&lt;/P&gt;&lt;P&gt;neu-roaming.officeapps.live.com&lt;/P&gt;&lt;P&gt;weu-roaming.officeapps.live.com&lt;/P&gt;&lt;P&gt;wus-roaming.officeapps.live.com&lt;/P&gt;&lt;P&gt;eus2-roaming.officeapps.live.com&lt;/P&gt;&lt;P&gt;scus-roaming.officeapps.live.com&lt;/P&gt;&lt;P&gt;ncus-roaming.officeapps.live.com&lt;/P&gt;&lt;P&gt;cus-roaming.officeapps.live.com&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;No&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;PRE&gt;13.75.42.223/32
13.67.53.38/32
13.69.159.30/32
40.74.50.25/32
104.40.28.30/32
137.116.77.120/32
40.84.149.239/32
65.52.210.135/32
40.122.129.128/32&lt;/PRE&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;TCP 80 &amp;amp; 443&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am also working with support for this issue however at the moment they cannot figure out why there is a decryption error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment i have bypassed ssl decryption for the following FQDN objects above.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Althought this resolve the issue i do want to unwrap the payload.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Addtionlay i was able to locate this document from microsoft .&amp;nbsp;&lt;/P&gt;&lt;P&gt;When SSL decryption is on and the soap connection get broken some office application just crush on startup .&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following reg changes resolve that however the soap decryption issue on the firewall remains.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.microsoft.com/en-us/help/4012623/office-applications-crash-when-you-open-an-irm-document-if-https-proxy" target="_self"&gt;https://support.microsoft.com/en-us/help/4012623/office-applications-crash-when-you-open-an-irm-document-if-https-proxy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think PAN need to do better work to document and create a full and holistic guide for office 365 deployments.&lt;/P&gt;&lt;P&gt;Current guides are short and does not include A to Z instruction or all the details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 12:19:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/164947#M53112</guid>
      <dc:creator>bpeeri</dc:creator>
      <dc:date>2017-07-06T12:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 SOAP error : Session End Reason decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/164960#M53114</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5299"&gt;@bpeeri&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The issue with O365 deployment guides of any type on NGFW from any company is how often they would need to be updated. You have Microsoft constantly making changes, Palo constantly updating things, and multiple different versions of Office software being used to function outside of O365 that you would need to cover. Not trying to make excuses for it really, but the amount of time that keeping any documentation up-to-date is insane, that's why I just linked an article that was from the 3.0 era a few days ago for another issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 13:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/office-365-soap-error-session-end-reason-decrypt-error/m-p/164960#M53114</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-06T13:44:03Z</dc:date>
    </item>
  </channel>
</rss>

