<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inbound ssl decryption - multi cert to single ip in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/210990#M61577</link>
    <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I figured the decryption follows the top/down. Do you have any thoughts why the traffic does not generate url any https logs for the unencrypted sites on this host when the decrpyt errors occur?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Apr 2018 16:25:18 GMT</pubDate>
    <dc:creator>clewis1</dc:creator>
    <dc:date>2018-04-19T16:25:18Z</dc:date>
    <item>
      <title>inbound ssl decryption - multi cert to single ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/210743#M61522</link>
      <description>&lt;P&gt;Hoping to get a little feed back regarding inbound ssl decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have beeing doing inbound ssl decryption to our public presense on version 8.0.7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Things have been going realitivley well but I am running into some issues and not sure if I can fix it at the firewall level. Where I am running into issues is when we have multiple certs applied on a load balancer to a single ip which is behind the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;ip address 1.2.3.4 (following sites all resolve to this ip this single ip addresss)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;decrypt rule 1 = use cert on lb (wildcard cert *.domain.com) to 1.2..3.4&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;, bob.domain.com, ie.domain.com (all using *.domain.com) - decrpyting as expected no issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;decrypt rule 2 =&amp;nbsp;&lt;SPAN&gt;use cert on lb (*.domain1.com) to 1.2.3.4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;domain1.com, cars.domain1.com - no decryption happening, traffic logs&amp;nbsp;show session end reason of decrpyt-error, no url traffic logs (for https, if site is http url logs will appear as expected)- but I can get to the website as normal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also other sites (&lt;A href="http://www.domain3.com" target="_blank"&gt;www.domain3.com&lt;/A&gt;, domain4,com, etc) on this&amp;nbsp; ip 1.2.3.4 with a different domain and no decrypt rule have same symptoms as decrypt rule 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is there a way to decrypt&amp;nbsp;to a single ip using multiple certs? Also is there an explanation behind why https url logs do not show when decryption erros occur in traffic logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All testing has been completed with IE and Chrome&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 14:04:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/210743#M61522</guid>
      <dc:creator>clewis1</dc:creator>
      <dc:date>2018-04-18T14:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: inbound ssl decryption - multi cert to single ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/210783#M61537</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41709"&gt;@clewis1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The rules are all analyzed in a top/down manner; therefore the first decryption policy that matches the source and destination is going to be the decryption policy that is applied. Unless you use the source as a differentation between the policies then something like this is not going to work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 15:57:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/210783#M61537</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-18T15:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: inbound ssl decryption - multi cert to single ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/210990#M61577</link>
      <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I figured the decryption follows the top/down. Do you have any thoughts why the traffic does not generate url any https logs for the unencrypted sites on this host when the decrpyt errors occur?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 16:25:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/210990#M61577</guid>
      <dc:creator>clewis1</dc:creator>
      <dc:date>2018-04-19T16:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: inbound ssl decryption - multi cert to single ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/211220#M61637</link>
      <description>&lt;P&gt;Add custom URL category (for single domain) in decryption policy.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 23:40:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/211220#M61637</guid>
      <dc:creator>blabla</dc:creator>
      <dc:date>2018-04-20T23:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: inbound ssl decryption - multi cert to single ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/211221#M61638</link>
      <description>&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Resolving-the-URL-Category-in-Decryption-When-Multiple-URLs-Use/ta-p/62573" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Resolving-the-URL-Category-in-Decryption-When-Multiple-URLs-Use/ta-p/62573&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 23:44:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inbound-ssl-decryption-multi-cert-to-single-ip/m-p/211221#M61638</guid>
      <dc:creator>blabla</dc:creator>
      <dc:date>2018-04-20T23:44:45Z</dc:date>
    </item>
  </channel>
</rss>

