<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption quits working. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216513#M62714</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90482"&gt;@BrianAult&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What does your Decryption Policy look like. If you have specified source-user as a matching criteria in the policy this would help explain why you are seeing an issue for instances where the user-mapping would change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would be able to correct this a number of ways; but lets take a look at how you've actually configured the policy before anything else.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jun 2018 15:49:52 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-06-04T15:49:52Z</dc:date>
    <item>
      <title>SSL Decryption quits working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216504#M62712</link>
      <description>&lt;P&gt;We have SSL Decryption setup and seems to work for awhile and then quits.&amp;nbsp; I cannot say for sure but it seems to be USER-ID related.&amp;nbsp; Out IT department logs in locally onto their laptops.&amp;nbsp; They might occasionally map a network drive or launch a program using run as their domain user account.&amp;nbsp; You might be browsing away and all the SSL is working (certificate shows it is issues by the Palo) and then all of a suddent it quits working.&amp;nbsp; By quits working it simply says the page cannot be found.&amp;nbsp; It does not give a certificate error or nothing.&amp;nbsp; Users are expeiriencing the same thing on a Terminal server, so maybe its because we are not using the agent for terminal server?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 15:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216504#M62712</guid>
      <dc:creator>BrianAult</dc:creator>
      <dc:date>2018-06-04T15:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption quits working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216513#M62714</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90482"&gt;@BrianAult&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What does your Decryption Policy look like. If you have specified source-user as a matching criteria in the policy this would help explain why you are seeing an issue for instances where the user-mapping would change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would be able to correct this a number of ways; but lets take a look at how you've actually configured the policy before anything else.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 15:49:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216513#M62714</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-04T15:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption quits working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216517#M62716</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have just one user in the source now, but before it was any.&amp;nbsp; So the only source criteria is our main subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Test-1; index: 2" {&lt;BR /&gt;from [ Trust GP-VPN ];&lt;BR /&gt;source [ 192.x.x.0/24 10.x.x.0/24 ];&lt;BR /&gt;source-region none;&lt;BR /&gt;to Untrust;&lt;BR /&gt;destination any;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user domain\user;&lt;BR /&gt;category any;&lt;BR /&gt;application/service 0:ssl/any/any/any;&lt;BR /&gt;action decrypt;&lt;BR /&gt;decryption-profile XXX-Test;&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 16:01:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216517#M62716</guid>
      <dc:creator>BrianAult</dc:creator>
      <dc:date>2018-06-04T16:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption quits working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216519#M62717</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90482"&gt;@BrianAult&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I wouldn't expect that to depend on user-id information then outside of the security policies that they may be matching.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I might imagine that part of your issue would actually be that you are only including 'ssl' as you would potentially stop decrypting when it gets identifies as another app-id. Most things will then complain because it was being presented with a cert generated by your firewall, and then starts getting a certificate generated the host.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 16:13:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216519#M62717</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-04T16:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption quits working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216524#M62720</link>
      <description>&lt;P&gt;It says Any for the service, is that what you mean by the second part?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 16:39:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216524#M62720</guid>
      <dc:creator>BrianAult</dc:creator>
      <dc:date>2018-06-04T16:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption quits working.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216525#M62721</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90482"&gt;@BrianAult&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Sorry I misread what you had configured and for some reason thought you were specifying 'ssl' as a app-id match criteria. What does your security rulebase look like; do you do a lot of user-id based rules?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 16:50:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-quits-working/m-p/216525#M62721</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-04T16:50:07Z</dc:date>
    </item>
  </channel>
</rss>

