<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Support for inspecting SSL message for kafka connect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/support-for-inspecting-ssl-message-for-kafka-connect/m-p/222975#M64100</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93695"&gt;@joshualouis911&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you decrypt the traffic then yes; but the firewall doesn't really care about the message itself and to the best of my knowledge doesn't have a great way of displaying/logging the actual message content.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2018 17:18:03 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-07-19T17:18:03Z</dc:date>
    <item>
      <title>Support for inspecting SSL message for kafka connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/support-for-inspecting-ssl-message-for-kafka-connect/m-p/222861#M64075</link>
      <description>&lt;P&gt;We are using Kafka for messaging and have a requirement to inspect the SSL message sent to kafka broker from kafka connect. Kafka using binary tcp protocol with kafka broker listeners on PLAINTEXT://9093&amp;nbsp;&lt;U&gt; &lt;/U&gt;(without SSL)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Can paloalto decrypt and inspect the kafka message content?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 20:17:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/support-for-inspecting-ssl-message-for-kafka-connect/m-p/222861#M64075</guid>
      <dc:creator>joshualouis911</dc:creator>
      <dc:date>2018-07-18T20:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Support for inspecting SSL message for kafka connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/support-for-inspecting-ssl-message-for-kafka-connect/m-p/222877#M64076</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93695"&gt;@joshualouis911&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Kafka as in Apache Kafka? That would depend highly on how you've configured it. By default Kafka doesn't even use encryption so you won't even need to worry about decrypting SSL traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the data itself isn't being encrypted outside of encrypted transport, then you should be able to view the data as soon as you decrypt the transport on the firewall.&amp;nbsp;Honestly though I have no idea how you would accomplish this on the firewall itself in any sort of useful format, as it isn't really designed to read the packet information and then output that for you. At beast you identify the Kafka traffic you are interested in and have it perform a packet capture on the traffic so that you could manually go back and read this information if required.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Out of curosity why would you worry about this on the firewall? The message would be plaintext on the broker (depending on how you configured it); and I assume if you are using kafka then this is internal and your organization should have access to the broker to do anything they wish with the information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 01:20:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/support-for-inspecting-ssl-message-for-kafka-connect/m-p/222877#M64076</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-19T01:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: Support for inspecting SSL message for kafka connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/support-for-inspecting-ssl-message-for-kafka-connect/m-p/222895#M64081</link>
      <description>&lt;P&gt;Yes Apache Kafka, Kafka is used&amp;nbsp;here to source data from a secured data center to cloud. The plan is to use Kafka connect on secured data center read data from database and transfer it to cloud we got paloalto in secured data center for inspecting the connection and traffic.&amp;nbsp;Since kafa&amp;nbsp;uses&amp;nbsp;tcp protocol will the message be in cleartext for Paloalto to inspect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 08:20:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/support-for-inspecting-ssl-message-for-kafka-connect/m-p/222895#M64081</guid>
      <dc:creator>joshualouis911</dc:creator>
      <dc:date>2018-07-19T08:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Support for inspecting SSL message for kafka connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/support-for-inspecting-ssl-message-for-kafka-connect/m-p/222975#M64100</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93695"&gt;@joshualouis911&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you decrypt the traffic then yes; but the firewall doesn't really care about the message itself and to the best of my knowledge doesn't have a great way of displaying/logging the actual message content.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 17:18:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/support-for-inspecting-ssl-message-for-kafka-connect/m-p/222975#M64100</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-19T17:18:03Z</dc:date>
    </item>
  </channel>
</rss>

