<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Inbound decryption and SMTP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-and-smtp/m-p/219102#M63284</link>
    <description>&lt;P&gt;PA does not support sending SMTP response code "541" while SSL Inbound decryption is enabled. It s normal behaviour that the PA just drop the session. You have to configure SSL Forward Proxy instead.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jun 2018 08:49:56 GMT</pubDate>
    <dc:creator>iweltag</dc:creator>
    <dc:date>2018-06-25T08:49:56Z</dc:date>
    <item>
      <title>SSL Inbound decryption and SMTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-and-smtp/m-p/213153#M62044</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does anybody have issues with ssl inbound decryption and setting the smtp decoder in AV Profile to reset-both (antivirus + wildfire)? When the firewall receives an email (with ssl/tls enc enabled) and successfully decrypt the message and found a virus the firewall is not sending a SMTP response code 541. The firewall just block/reset the session. so the sender will never be notified. Without ssl/tls enabled (ssl/tls disabled between spam/av &amp;lt;--&amp;gt; reveiving mailserver) the firewall send a SMTP response code 541.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mail server (sending) ---SSL/TLS---&amp;gt; Spam/Antivirus Scan (Cloud-based Internet Security Services) ---SSL/TLS---&amp;gt; PA - Firewall ---&amp;gt; Mail server (receiving)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just wondering - i have also opened a case with pa support. we are running on panos 8.0.8.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;bastian&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 14:21:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-and-smtp/m-p/213153#M62044</guid>
      <dc:creator>iweltag</dc:creator>
      <dc:date>2018-05-07T14:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inbound decryption and SMTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-and-smtp/m-p/219102#M63284</link>
      <description>&lt;P&gt;PA does not support sending SMTP response code "541" while SSL Inbound decryption is enabled. It s normal behaviour that the PA just drop the session. You have to configure SSL Forward Proxy instead.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 08:49:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-decryption-and-smtp/m-p/219102#M63284</guid>
      <dc:creator>iweltag</dc:creator>
      <dc:date>2018-06-25T08:49:56Z</dc:date>
    </item>
  </channel>
</rss>

