<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption using incorrect security policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8937#M6533</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you go.&amp;nbsp; The rules work fine with no decryption but when it is turned on for some reason it jumps over "Netit".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="netit.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/18946_netit.png" style="height: 19px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="unauth.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/18956_unauth.png" style="height: 10px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Apr 2015 13:06:39 GMT</pubDate>
    <dc:creator>ClintL</dc:creator>
    <dc:date>2015-04-02T13:06:39Z</dc:date>
    <item>
      <title>SSL decryption using incorrect security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8935#M6531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am testing out SSL decryption on a few categories.&amp;nbsp; For now I am using a system generated certificate and it works in decrypting the categories I have selected.&amp;nbsp; The problem is that once it is decrypted, it doesn't use the proper security policy.&amp;nbsp; We have AD integration and URL filtering set up between certain groups.&amp;nbsp; My user ID has elevated browsing privileges but after the session is decrypted it uses the policy I have set up when the firewall doesn't know who the user is so I am getting blocked.&amp;nbsp; Any idea why it wouldn't use the correct security policy when the log view and blocked page are showing my user ID?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="18896" alt="ssldecrypt.png" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/18896_ssldecrypt.png" style="height: 379px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="18877" alt="ssldecryptblocked.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/18877_ssldecryptblocked.png" style="height: 122px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Mar 2015 18:21:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8935#M6531</guid>
      <dc:creator>ClintL</dc:creator>
      <dc:date>2015-03-31T18:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption using incorrect security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8936#M6532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Clint&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you also include a screenshot of the security policy?&lt;/P&gt;&lt;P&gt;The security policies are processed top to bottom with the first match (not "best" match) being the rule that is used to pass traffic, so if your top rule does not have a source user restriction this would be normal.&lt;/P&gt;&lt;P&gt;have you set that rule to use source user "unknown" or "any" ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 12:28:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8936#M6532</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-04-02T12:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption using incorrect security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8937#M6533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you go.&amp;nbsp; The rules work fine with no decryption but when it is turned on for some reason it jumps over "Netit".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="netit.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/18946_netit.png" style="height: 19px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="unauth.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/18956_unauth.png" style="height: 10px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 13:06:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8937#M6533</guid>
      <dc:creator>ClintL</dc:creator>
      <dc:date>2015-04-02T13:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption using incorrect security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8938#M6534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My guess is that the app is now "web-browsing" due to decryption, but the port is still 443. You're using application-default as the service for the first rule (and I'm assuming "web-browsing" is included in that filter) so that would only match if web was on 80, but I'm guessing that you have port 443 included in the "service-web" service group on the other rule, and "web-browsing" included in "web-services".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 15:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8938#M6534</guid>
      <dc:creator>rfrazier</dc:creator>
      <dc:date>2015-04-02T15:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption using incorrect security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8939#M6535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you may be correct, sir.&amp;nbsp; I'll give it a try here shortly and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: That was it.&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 15:28:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-using-incorrect-security-policy/m-p/8939#M6535</guid>
      <dc:creator>ClintL</dc:creator>
      <dc:date>2015-04-02T15:28:49Z</dc:date>
    </item>
  </channel>
</rss>

