<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decryption policy options explanation required. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198216#M58855</link>
    <description>&lt;P&gt;The certificate profile has options to 'block unsupported' suites and ciphers, if you diable those options unsupported certifcates will be allowed to pass through&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can also add sites to the SSL Decrypt Exclusion list (device &amp;gt; certificate management)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;some certificates may be pinned or have other features that are not supported&lt;/P&gt;</description>
    <pubDate>Thu, 01 Feb 2018 14:47:54 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-02-01T14:47:54Z</dc:date>
    <item>
      <title>Decryption policy options explanation required.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198099#M58833</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am reading about decryption policy and have some questions in my mind, so looking for some answers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- In order to apply the decryption profile, do I need to have action set to decrypt&amp;nbsp;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2- what is the advantage if I have a decrypt policy with options set to:&lt;/P&gt;&lt;P&gt;a) Action: No decrypt (with no profile) &amp;lt;-- is not it same as if it was not created !&lt;/P&gt;&lt;P&gt;b) Action: No decrypt (with profile) &amp;lt;-- if Q1 is yes&lt;/P&gt;&lt;P&gt;c) Action: Decrypt (with no profile) &amp;lt;-- In this case only useful for decrypt mirror/forwarding ? or will it go now to the other security policies to apply other possible profiles (e.g. Anti-virus, file block, data filter, etc) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 06:41:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198099#M58833</guid>
      <dc:creator>Xtreme</dc:creator>
      <dc:date>2018-02-01T06:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption policy options explanation required.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198130#M58838</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71687"&gt;@Xtreme&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you will need a decryption policy before decryption will be applied to a session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The no-decryptpolicy is usually used to exclude a subset of oytherwise decrypted traffic (eg. decrypt everything except financial url category because it is privacy sensitive)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The decryption profile is used to help the firewall decide what to do if something is unusual or wrong with a certificate&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some certificates may not be signed by a trusted source or expired,some may be using a weak cipher (3des, md5) &lt;/P&gt;
&lt;P&gt;The profile will help you block (or not) these connections as they should be considered as suspicious.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 09:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198130#M58838</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-01T09:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption policy options explanation required.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198176#M58846</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71687"&gt;@Xtreme&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Touching off of what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;pointed out earlier, I've never seen a firewall configured for SSL Decryption that&amp;nbsp;&lt;EM&gt;doesn't&lt;/EM&gt; have some sort of 'No-Decrypt' policy. Exactly for the points that reaper pointed out for categories such as Financial information, health and banking and he such. However most will also come across differerent applications or websites that won't work nicely with SSL Decryption. PA builds in a decent SSL Decryption Exclusion list to try and assist with this, however there are some services (primarly when using client certs or pinned certs for auth) that simply won't work when run through the decryption policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 13:00:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198176#M58846</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-01T13:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption policy options explanation required.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198198#M58852</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;, nice info....&amp;nbsp; but can i just ask...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are often adding sites to the no-decrypt rule as the site becomes unreachable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am i missing something here...&lt;/P&gt;&lt;P&gt;Does the PA not have the option to see that it cannot be decrypted and just pas the traffic through as normal..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried to work out why the decryption is failing by comparing packets in wireshark, and it seems that what is being offered is available on the PA...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any other options for checking decrypt failures...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again...&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 14:06:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198198#M58852</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-01T14:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption policy options explanation required.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198216#M58855</link>
      <description>&lt;P&gt;The certificate profile has options to 'block unsupported' suites and ciphers, if you diable those options unsupported certifcates will be allowed to pass through&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can also add sites to the SSL Decrypt Exclusion list (device &amp;gt; certificate management)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;some certificates may be pinned or have other features that are not supported&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 14:47:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198216#M58855</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-01T14:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption policy options explanation required.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198221#M58857</link>
      <description>&lt;P&gt;Thanks guys. However, I want your input regarding the following statements (True or Falese):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- No-Decryption action with profile exist --&amp;gt; this requires that certifiacate has no issue, otherwise drop connection.&lt;/P&gt;&lt;P&gt;2- Decrypt action with profile or without profile --&amp;gt; this traffic if compliant with profile (if exist) will go over the security policy to see if a match exist then other defined&amp;nbsp;profiles such as anti-virus, file blocking profiles will apply to the decrypted traffic.&lt;/P&gt;&lt;P&gt;3- &amp;nbsp;For decrypt mirror to work correctly, I need to create decryption policy with action set to "Decrypt" and Profile with Decrypt mirror "Enabled" (regardeless of the certificate status and/or other security policies and profiles)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* If false what is the correct behaviour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 14:54:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-policy-options-explanation-required/m-p/198221#M58857</guid>
      <dc:creator>Xtreme</dc:creator>
      <dc:date>2018-02-01T14:54:44Z</dc:date>
    </item>
  </channel>
</rss>

