<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Troubleshooting SSL decryption failure of a website in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/194714#M58230</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Sounds like you on are on the correct path. I'm sure many of us are willing to help, but would need to see the pcaps or any other information you are willing to share. I would agree that its probably a quick redirect somewhere that is causing the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try looking at the Unified logs from a client and see if that can tell the whole story.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jan 2018 22:08:44 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-01-10T22:08:44Z</dc:date>
    <item>
      <title>Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/194673#M58225</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using panOS 8.0.7 , Pan-DB URL filtering, and SSL decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are K12 education and use many Chromebooks in the organization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to use a system called Clever to have our students log into their Chromebooks by scanning a QR code.&amp;nbsp; The problem is I cannot get the program to work. (&lt;A href="https://clever.com/" target="_blank"&gt;https://clever.com/&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know the issue is with the SSL decryption because if I exclude the device from decryption, things works correctly and I am prompted to scan my QR code.&amp;nbsp; With decryption turned on, I get a hung screen and can't proceed to the next step of login.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have worked with Palo TAC and Clever support and haven't been able to get it working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have many URLs excluded from decryption that Google and Clever say need to be bypassed from decyption as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My next thoughts would be to run some packet captures, but I'm not that familiar with Wireshark analysis.&amp;nbsp; I am thinking I need to look at the headers to see if there are any other URLs which I don't have in my exclude list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under the traffic logs, for the sessions, I can see some entries are being decrypted.&amp;nbsp; In the URL filtering logs, I can see the sessions are not being decrypted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have any thoughts on this, or would be willing to help out?&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 18:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/194673#M58225</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2018-01-10T18:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/194714#M58230</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Sounds like you on are on the correct path. I'm sure many of us are willing to help, but would need to see the pcaps or any other information you are willing to share. I would agree that its probably a quick redirect somewhere that is causing the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try looking at the Unified logs from a client and see if that can tell the whole story.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 22:08:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/194714#M58230</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-10T22:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/194970#M58283</link>
      <description>&lt;P&gt;OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can do a packet capture on the Palo with and without decryption turned on, so I'd hae 2 sets of captures (drop, firewall, transmit, receive)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which ones would you like me to upload here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:10:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/194970#M58283</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2018-01-12T17:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/194971#M58284</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Do you have the unified logs of the attempts made with SSL on and off? I think that may be a better start. Sorry for the confusion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please filter them by the source IP of the client making the attempts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you would rather perform this live via webex or something. Let me know when you might have time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/194971#M58284</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-12T17:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195005#M58291</link>
      <description>&lt;P&gt;Here are the 2 screenshots.&amp;nbsp; I've got the excel files also, but don't know how to upload them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Good" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13209i6007CAC3A5074F50/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Good.JPG" alt="Good" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Good&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fail" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13208i263B3307807D161E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Fail.JPG" alt="Fail" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Fail&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 21:37:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195005#M58291</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2018-01-12T21:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195015#M58293</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;How are you bypassing decryption? For example when I know its a website, I create a custom URL and add the sites I dont want to decrypt there. And then create a decryption policy above my decrypt everything and set it to no decrypt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm assuming you have clever.com and *.clever.com listed as no decrypt?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 21:56:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195015#M58293</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-12T21:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195022#M58297</link>
      <description>&lt;P&gt;On the second line from the top in the fail screenshot, there is traffic to&amp;nbsp;13.57.157.75 that was decrypted, when I looked it up, it belonged to clever.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/ip-address/13.57.157.75/information/" target="_blank"&gt;https://www.virustotal.com/en/ip-address/13.57.157.75/information/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/domain/clever.com/information/" target="_blank"&gt;https://www.virustotal.com/en/domain/clever.com/information/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would say it might be a no decrypt rule that is not getting hit for some reason.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 22:13:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195022#M58297</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-12T22:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195313#M58360</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've got all of my URLs in a custome URL category called "no decrypt".&amp;nbsp; I've got my decryption rules with the no decryption up top&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="decrypt.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13248iC0009541806B77F3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="decrypt.JPG" alt="decrypt.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Decryption rule #1 is for bypass.&amp;nbsp; All other traffic gets decrypted by rule #5.&amp;nbsp; Rules 2-4 don't apply in this situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also just verified that I have the following in my "no-decryption" URL category:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*.clever.com&lt;/P&gt;&lt;P&gt;*.clever.com/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wasn't sure if I needed both URLs in a decryption bypass rule, so I have both.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 14:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195313#M58360</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2018-01-16T14:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195314#M58361</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The No-Decrypt URL should be"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*.clever.com&lt;/P&gt;&lt;P&gt;clever.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 15:18:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195314#M58361</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-16T15:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195346#M58365</link>
      <description>&lt;P&gt;OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that fixed it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm confused now about how to enter URLs into the Palo -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for adding URLs to a custom category rules, I read here on Palo's site to enter them as&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*.domain&lt;/P&gt;&lt;P&gt;*.domain/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to catch everything.&amp;nbsp; This would be if I wanted to recategorize a URL from a blocked to an allowed custom-URL category.&amp;nbsp; Or vice-versa.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought adding them to a no-decryption rule would be the same thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 17:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195346#M58365</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2018-01-16T17:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting SSL decryption failure of a website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195352#M58367</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;You are correct, adding URL's is the same for either. Here is hte breakdown of what I suggested:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*.domain.com = will allow anything infront of hte domain.com ,i.e. &lt;A href="http://www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;, mail.domain.com, etc.&lt;/P&gt;&lt;P&gt;domain.com = will allow anything if it doesnt have a prefix, i.e. domain.com, domain.com/whatever, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So one just allows for a prefix prior to the domain name. While I cannot find the article, its best practice to perform it the way i have it outlined.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that clears things up and glad its working for you!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 18:02:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ssl-decryption-failure-of-a-website/m-p/195352#M58367</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-16T18:02:31Z</dc:date>
    </item>
  </channel>
</rss>

