<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: what is the best for social-networking category ,Decrypt or no decrypt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/227255#M65401</link>
    <description>&lt;P&gt;Thank you for your reply&lt;/P&gt;</description>
    <pubDate>Thu, 16 Aug 2018 07:51:59 GMT</pubDate>
    <dc:creator>AhmedEmam</dc:creator>
    <dc:date>2018-08-16T07:51:59Z</dc:date>
    <item>
      <title>what is the best for social-networking category ,Decrypt or no decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/226872#M65310</link>
      <description>&lt;P&gt;Dears&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my company ,unfortunately, allow facebook.com website&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we note when do "SSL Decryption" for social-networking category ,There is huge utilization on CPU (Up to 85%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the better for this case as design &amp;nbsp;: Decrypt Facebook or no decrypt ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if we do "no-decrypt" ,Can palo alto to apply the policy of deny for some application on facebook such as "Facebbok-chat ,..."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 12:29:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/226872#M65310</guid>
      <dc:creator>AhmedEmam</dc:creator>
      <dc:date>2018-08-13T12:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: what is the best for social-networking category ,Decrypt or no decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/226913#M65318</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84509"&gt;@AhmedEmam&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;SSL Decryption can take a hit on smaller boxes that don't have much processing to spare; and depending on the amount of traffic you pass to Facebook you would expect to see a spike when you first start decrypting traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The firewall won't be able to reliably look into the traffic and properly identify facebook-chat instead of normal 'facebook'. This makes for a broken experiance as users will be constantly switching back and forth between a working facebook-chat and a non-working facebook-chat as the firewall is able to identify the app-id as traffic passes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would personally recommend that you keep decrypting the traffic, 85% utilization is perfectly fine for the firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 14:43:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/226913#M65318</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-13T14:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: what is the best for social-networking category ,Decrypt or no decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/227145#M65365</link>
      <description>&lt;P&gt;Thank you for your reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would&amp;nbsp; think that 85% is very high because exceed Max.= 80%&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when try to implement decryption ,I note the palo alto can down the&amp;nbsp;"Facebook-chat" as example and permit the facebook .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is problem or (Bad desgin) if cancle decryption ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again thank you for your reply &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 09:40:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/227145#M65365</guid>
      <dc:creator>AhmedEmam</dc:creator>
      <dc:date>2018-08-15T09:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: what is the best for social-networking category ,Decrypt or no decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/227160#M65375</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84509"&gt;@AhmedEmam&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;85% would be high if it's sustained, and it certainly&amp;nbsp;poses a question on whether a spike in traffic would push the CPU even higher. If it's a momentary spike to 85% and it curbs off right away, I wouldn't be worried about it; if you are at a sustained&amp;nbsp;85% and spiking higher then that's an actual issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not decrypting the traffic you lose insight into what the traffic is actually doing/is. At that point there is no knowing whether the traffic is simply&amp;nbsp;normal social media traffic or if a malicious attachment someone got through email is using facebook to host a malicious file masquerading&amp;nbsp;as an image. Most companies also have different policies in place on different parts of Facebook; for example they might let you go to Facebook, but not chat or access any Facebook games.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whether or not you should decrypt this traffic depends on multiple things that matter in varying degrees depending on the company.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 13:22:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/227160#M65375</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-15T13:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: what is the best for social-networking category ,Decrypt or no decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/227255#M65401</link>
      <description>&lt;P&gt;Thank you for your reply&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 07:51:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-for-social-networking-category-decrypt-or-no/m-p/227255#M65401</guid>
      <dc:creator>AhmedEmam</dc:creator>
      <dc:date>2018-08-16T07:51:59Z</dc:date>
    </item>
  </channel>
</rss>

