<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption alert or log in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/198785#M58984</link>
    <description>&lt;P&gt;That looks like it could do the trick! just tested it out and its the nearest thing we are going to get&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Mon, 05 Feb 2018 09:13:48 GMT</pubDate>
    <dc:creator>Carpetright</dc:creator>
    <dc:date>2018-02-05T09:13:48Z</dc:date>
    <item>
      <title>SSL decryption alert or log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/191872#M57726</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use SSL decryption and from time to time we have issue with web sites and apps not working because we are decrypting their traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If its a web site that doesnt like ssl decryption most of the time the end user will get the relevant response page, but our issue is with applications or windows apps that &lt;SPAN&gt;doesnt like ssl decryption because we dont get&amp;nbsp;a response page we just get an error in the app&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When we check the firewall there is nothing clear in the logs (Traffic and or URL filtering) that SSL decryption is causing issues, so troubleshootingtakes a lot longer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there anyway that we can get logs for SSL decryption issues?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this makes sense&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 15:15:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/191872#M57726</guid>
      <dc:creator>Carpetright</dc:creator>
      <dc:date>2017-12-15T15:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption alert or log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/191893#M57729</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way I have done it inthe past is make sure nothing is trying to reach out from that PC to the internet and start the intended action, i.e. windows updates. Then I filter the unified logs to see which URL they are reaching out to. From there is a bit of a hit or miss to see which URL's I need to allow. Once I find it I usually have to allow the application and make sure the URL's are not being decrypted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps and makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 16:40:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/191893#M57729</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-12-15T16:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption alert or log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/198533#M58923</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thats kinda what i have been doing but its still a pain and i was hoping there might be an easier way to find out if a site/app doesnt like having its SSL decrypted&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 14:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/198533#M58923</guid>
      <dc:creator>Carpetright</dc:creator>
      <dc:date>2018-02-02T14:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption alert or log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/198537#M58926</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I think that is something we all want. I dont know of any way except a user notifying me :(.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 15:14:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/198537#M58926</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-02T15:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption alert or log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/198649#M58953</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43712"&gt;@Carpetright&lt;/a&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;They did release a few new session_end_reasons in 7.1 that actually do&amp;nbsp;&lt;EM&gt;help&lt;/EM&gt; in seeing when a website has issues with decryption. It still isn't perfect, and doesn't even necissarly guarentee they are having an issue, but it at least gives you something to look for.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;( session_end_reason eq decrypt-unsupport-param ) or ( session_end_reason eq decrypt-cert-validation ) or ( session_end_reason eq decrypt-error )&lt;/PRE&gt;</description>
      <pubDate>Fri, 02 Feb 2018 22:44:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/198649#M58953</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-02T22:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption alert or log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/198785#M58984</link>
      <description>&lt;P&gt;That looks like it could do the trick! just tested it out and its the nearest thing we are going to get&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2018 09:13:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alert-or-log/m-p/198785#M58984</guid>
      <dc:creator>Carpetright</dc:creator>
      <dc:date>2018-02-05T09:13:48Z</dc:date>
    </item>
  </channel>
</rss>

