<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site / urls you don't want to decrypt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-urls-you-don-t-want-to-decrypt/m-p/230828#M66305</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I like your decryption rules way more than the predefined exclusions. Thats why I disable all of them in most cases (and this has to be done again with every content update - at least for the new ones - which is a little annyoing).&lt;/P&gt;&lt;P&gt;At least since PAN-OS 8 we can control these predefined exclusions, but with the decryption policy I have more control for these exclusions because most of the time (in my case) the exclusion needs to be very specific and not a general one like with the exclusion list because when the exclusion is required from one computer/subnet/zone I don't care if the connection from anywhere else fails (as it is probably blocked in the security policy anyway).&lt;/P&gt;&lt;P&gt;Just my two cents ...&lt;/P&gt;</description>
    <pubDate>Fri, 14 Sep 2018 08:03:25 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-09-14T08:03:25Z</dc:date>
    <item>
      <title>Site / urls you don't want to decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-urls-you-don-t-want-to-decrypt/m-p/230797#M66295</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a set of decrypt rules&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 to no decrypt based on&amp;nbsp;&lt;/P&gt;&lt;P&gt;src address&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;dst address&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;url - the usl is from custom objects / url category where I add in url's lile *.lync.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then i do my decrypt line so the above gets hit first and then the decrypt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also notice there is device / cert management / ssl decrypt exclusion &amp;lt;&amp;lt; which seems to be a master list of urls to no decrypt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;should I be usine this list or my way above is there an advantage ?&amp;nbsp; Not sure why I didn't start using the exclusion list from the start&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 01:22:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-urls-you-don-t-want-to-decrypt/m-p/230797#M66295</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-09-14T01:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Site / urls you don't want to decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-urls-you-don-t-want-to-decrypt/m-p/230828#M66305</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I like your decryption rules way more than the predefined exclusions. Thats why I disable all of them in most cases (and this has to be done again with every content update - at least for the new ones - which is a little annyoing).&lt;/P&gt;&lt;P&gt;At least since PAN-OS 8 we can control these predefined exclusions, but with the decryption policy I have more control for these exclusions because most of the time (in my case) the exclusion needs to be very specific and not a general one like with the exclusion list because when the exclusion is required from one computer/subnet/zone I don't care if the connection from anywhere else fails (as it is probably blocked in the security policy anyway).&lt;/P&gt;&lt;P&gt;Just my two cents ...&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 08:03:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-urls-you-don-t-want-to-decrypt/m-p/230828#M66305</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-14T08:03:25Z</dc:date>
    </item>
  </channel>
</rss>

