<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA SSL decryption  for web traffic and squid in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175583#M55011</link>
    <description>&lt;P&gt;Interesting, but I seem to get all that by doing it before. Plus I don't have the&amp;nbsp;&lt;SPAN&gt;XFF value setup ..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alex&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Sep 2017 07:42:20 GMT</pubDate>
    <dc:creator>Alex_Samad</dc:creator>
    <dc:date>2017-09-08T07:42:20Z</dc:date>
    <item>
      <title>PA SSL decryption  for web traffic and squid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175514#M54998</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where should I be doing the decryption&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;client -&amp;gt; pa (l3) -&amp;gt; squid -&amp;gt; internet&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;client -&amp;gt; squid -&amp;gt; pa (l3) -&amp;gt; internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thinking the first one, then I can also see who is making the request&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 23:46:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175514#M54998</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-09-07T23:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: PA SSL decryption  for web traffic and squid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175563#M55005</link>
      <description>&lt;P&gt;The problem with on the suggested solution is that palo then only sees http-proxy traffic and nothing else - no url logs and decryption isnt'possible this way.&lt;/P&gt;&lt;P&gt;So you have to use your second possibility.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 05:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175563#M55005</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-09-08T05:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: PA SSL decryption  for web traffic and squid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175565#M55006</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm already doing 1 but with out decrypt and it works fine, it looks into the info and knows its in tunnel mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 05:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175565#M55006</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-09-08T05:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: PA SSL decryption  for web traffic and squid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175573#M55007</link>
      <description>&lt;P&gt;So you have url logs or only the app http-proxy in the traffic log with the username?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:16:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175573#M55007</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-09-08T07:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: PA SSL decryption  for web traffic and squid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175574#M55008</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With what i have right now, which is no decryption i see and can filter on application type so google-mail , facebook chat, it looks inside the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My policy is basically&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any work ip -&amp;gt; to my proxy server ip and port 3128 or 8080 as the service ports, with application set to general internat. I have had to add things as some sites are not under general internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can also who is the user logged into the client pc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:19:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175574#M55008</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-09-08T07:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: PA SSL decryption  for web traffic and squid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175577#M55009</link>
      <description>&lt;P&gt;Ok, in this case I have to thank you for teaching me something new.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Till your post I thought the way to do this in combination with a proxy is&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client --&amp;gt; proxy --&amp;gt; palo&lt;/P&gt;&lt;P&gt;And then use the x-forwarded-for http header to identify the user on the firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As described here:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/identify-users-connected-through-a-proxy-server" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/identify-users-connected-through-a-proxy-server&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:26:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175577#M55009</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-09-08T07:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: PA SSL decryption  for web traffic and squid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175583#M55011</link>
      <description>&lt;P&gt;Interesting, but I seem to get all that by doing it before. Plus I don't have the&amp;nbsp;&lt;SPAN&gt;XFF value setup ..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alex&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175583#M55011</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-09-08T07:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: PA SSL decryption  for web traffic and squid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175773#M55050</link>
      <description>&lt;P&gt;Hi Alex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you already have this setup, it should be pretty easy to test if this now also works with decryption (I am also interessted in your results, even if I don't like these traditional proxy servers &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt; &amp;nbsp;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: Removed sensless sentence&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Sep 2017 07:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175773#M55050</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-09-10T07:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: PA SSL decryption  for web traffic and squid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175783#M55055</link>
      <description>&lt;P&gt;I'm not running the proxies in transparent mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and I want all traffic going to proxy for outbound traffic&lt;/P&gt;</description>
      <pubDate>Sun, 10 Sep 2017 02:15:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ssl-decryption-for-web-traffic-and-squid/m-p/175783#M55055</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-09-10T02:15:55Z</dc:date>
    </item>
  </channel>
</rss>

