<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL alerting without SSL decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-alerting-without-ssl-decryption/m-p/213945#M62200</link>
    <description>&lt;P&gt;Paloalto Firewalls are logging also https URLs (at least the domain name) even without decryption. What does your security policy look like? Do you have the URL filtering profile only applied to a rule where web-browsing is configured but not on ssl traffic?&lt;/P&gt;</description>
    <pubDate>Thu, 10 May 2018 17:04:17 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-05-10T17:04:17Z</dc:date>
    <item>
      <title>URL alerting without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-alerting-without-ssl-decryption/m-p/212159#M61893</link>
      <description>&lt;P&gt;Hello all! I've got a question on URL category alerting. I can set up alerting for malware and phishing categories, for example. I get the alerts if the site is HTTP only. I don't seem to get them if it is HTTPS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is this... Shouldn't the domain names still get flagged for those categories just on the DNS query? Not only that but domain names are not obfuscated in HTTPS traffic. Shouldn't they still be alerting regardless?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need to alert on sites for our clients who mostly want our device in TAP mode and I'm super confused on this. Thanks in advance for any help you get provide!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 20:36:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-alerting-without-ssl-decryption/m-p/212159#M61893</guid>
      <dc:creator>BrendanOConnell</dc:creator>
      <dc:date>2018-04-27T20:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: URL alerting without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-alerting-without-ssl-decryption/m-p/213945#M62200</link>
      <description>&lt;P&gt;Paloalto Firewalls are logging also https URLs (at least the domain name) even without decryption. What does your security policy look like? Do you have the URL filtering profile only applied to a rule where web-browsing is configured but not on ssl traffic?&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 17:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-alerting-without-ssl-decryption/m-p/213945#M62200</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-10T17:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: URL alerting without SSL decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-alerting-without-ssl-decryption/m-p/214315#M62288</link>
      <description>&lt;P&gt;The DNS query is not directly matched against a http(s) connection as that would require too much correlation in most cases&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;instead (and this is far more efficient), we do inspect certificate CN or SNI hostname in the handshake for ssl IF the session is matched against a security policy where url filtering is enabled for ssl&amp;nbsp; (provided you are on a PAN-OS that is not older than 6.0)&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 13:27:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-alerting-without-ssl-decryption/m-p/214315#M62288</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-05-15T13:27:52Z</dc:date>
    </item>
  </channel>
</rss>

