<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabling SSL Decryption not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-ssl-decryption-not-working/m-p/192052#M57748</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79304"&gt;@JohnSysAd&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSL decryption enables a proxy service, you can tell that proxy service to decrypt inbound or outbound, or not decrypt&lt;/P&gt;
&lt;P&gt;But since your policy still matches a proxy rule, the session will still be handed off to the proxy: so if you don't want ssl decryption, don't create a decryption policy&lt;/P&gt;
&lt;P&gt;If you want to bypass decryption on some url categories (finance may not be allowed by law depending on your sector for example) while stil ldecryption everything else, you can create a no-decrypt policy to not inspect those sessions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;</description>
    <pubDate>Mon, 18 Dec 2017 11:57:55 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-12-18T11:57:55Z</dc:date>
    <item>
      <title>Disabling SSL Decryption not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-ssl-decryption-not-working/m-p/192045#M57747</link>
      <description>&lt;P&gt;Hey everybody!&lt;/P&gt;&lt;P&gt;After watching all tutorials and reading all PAN's walkthroughts, I still &lt;STRONG&gt;&lt;EM&gt;fail to disable the SSL Inspection&lt;/EM&gt;&lt;/STRONG&gt; (decryption) on all of the outgoing (or any..) traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;This is my decryption profile:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 300px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13011i729B544ACA84B8D6/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 300px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13012i2642A846FCA1F871/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;*Rest tabs are default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;This is my Decryption Policy:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13013i2BD7CB4FB3142E7A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;*My Security Policy is just any,any,allow (nothing special) and my traffic is never blocked - as I expect.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point, I expect every https request of&amp;nbsp;&lt;STRONG&gt;any&lt;/STRONG&gt; website to be &lt;STRONG&gt;not inspected&lt;/STRONG&gt;. Meaning, now if I open up my Chrome and go to (lets say)&amp;nbsp; &lt;A href="https://www.wikipedia.org/" target="_self"&gt;https://www.wikipedia.org/&lt;/A&gt;&amp;nbsp;and check the &lt;EM&gt;Security Overview&lt;/EM&gt; (F12 -&amp;gt; Security) - I should see the 'real' Certificate of this website. Same result should apply to the alternative of using &lt;STRONG&gt;openssl&lt;/STRONG&gt;&amp;nbsp;command for requesting https websites instead of just browing via Browser Software like Chrome. (openssl s_client -connect wikipedia.org:443)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;The issue:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;While doing both of the described above, I still get the PAN's Certificate (*issued by PAN) where I try not to apply the decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Capture:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13014i82EE649751A2C58C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;using openssl:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13015iDAEE1462D30C70DC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I even explicitly excluded &lt;A href="http://www.wikipedia.org" target="_blank"&gt;www.wikipedia.org&lt;/A&gt; and it did not help:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13016i4D0FBE5564F6C004/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What am I missing? Yhelp &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;J.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2017 11:28:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-ssl-decryption-not-working/m-p/192045#M57747</guid>
      <dc:creator>JohnSysAd</dc:creator>
      <dc:date>2017-12-18T11:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SSL Decryption not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-ssl-decryption-not-working/m-p/192052#M57748</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79304"&gt;@JohnSysAd&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSL decryption enables a proxy service, you can tell that proxy service to decrypt inbound or outbound, or not decrypt&lt;/P&gt;
&lt;P&gt;But since your policy still matches a proxy rule, the session will still be handed off to the proxy: so if you don't want ssl decryption, don't create a decryption policy&lt;/P&gt;
&lt;P&gt;If you want to bypass decryption on some url categories (finance may not be allowed by law depending on your sector for example) while stil ldecryption everything else, you can create a no-decrypt policy to not inspect those sessions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2017 11:57:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-ssl-decryption-not-working/m-p/192052#M57748</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-18T11:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SSL Decryption not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-ssl-decryption-not-working/m-p/192056#M57749</link>
      <description>&lt;P&gt;hey reaper and thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, your second suggestion (bypassing specific urls) did not work, i've tried it earlier. That was the reason I generally tried to bypass&amp;nbsp;&lt;STRONG&gt;everything&lt;/STRONG&gt; in order to troubleshoot the issue..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, I &lt;STRONG&gt;disabled&lt;/STRONG&gt;&amp;nbsp;all Decryption Policies and still getting decrypted for some reason.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cap:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13018iF1680E3328455B19/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13017i38BF67F7CD80B5B0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and ofcourse I can still see PAN's Certificate using the F12 on browser / openssl requests for connection on all websites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition, I think I didn't quite understand what u were saying with the proxy service tunneling, and even so, I just did what you suggested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Did I miss anything again? Do you have another idea?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;J.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2017 12:10:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-ssl-decryption-not-working/m-p/192056#M57749</guid>
      <dc:creator>JohnSysAd</dc:creator>
      <dc:date>2017-12-18T12:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SSL Decryption not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-ssl-decryption-not-working/m-p/192060#M57750</link>
      <description>&lt;P&gt;This may be a silly question, but did you commit your changes and clear all ssl sessions?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Disabling decryption does not immediately stop all decryption as it only applies to new sessions created after the commit went through, but old sessions will keep being decrypted until they end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it's perfectly possible for some sessions to remain that are being decrypted minutes or possibly hours (as tcp sessions could live up to 24 hours) after committing&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bypassing some categories will not decrypt them, but they will still be handed off to the proxy as long as they match a&amp;nbsp;rule in the decryption&amp;nbsp;policy so you will still see the certificate, but the proxy service will simply not look inside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also, try closing your browser and opening the page fresh to esure the browser hasn't cached the certificate somehow&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2017 12:17:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-ssl-decryption-not-working/m-p/192060#M57750</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-18T12:17:45Z</dc:date>
    </item>
  </channel>
</rss>

