<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption just some users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231183#M66382</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/95192"&gt;@PedroPablo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The screenshot might be misleading ... "Source users" doesn't mean you have to add each user&amp;nbsp; individually &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As Otakar mentioned you can create AD groups and use those in your decryption policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 18 Sep 2018 07:18:22 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2018-09-18T07:18:22Z</dc:date>
    <item>
      <title>SSL Decryption just some users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231075#M66349</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm struggling thinking how i can do this. I've implemented SSL Decryption in the Palo Alto FW and i just tried with two IP's&amp;nbsp; with a succesful result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now i would like to open the range. I want to apply that decryption rule to an OU of my domain but i don't know how to do it. Well, actually, i don't know if it's possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, the thing is just to apply that rule to a group of users that i want to keep doing tests and i can't do it with IP addresses because we have DHCP deployed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone help me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 14:07:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231075#M66349</guid>
      <dc:creator>PedroPablo</dc:creator>
      <dc:date>2018-09-17T14:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption just some users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231090#M66350</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/95192"&gt;@PedroPablo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, in your decription policy rule you can define your source users :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-09-17_16-41-42.png" style="width: 702px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16666i40A8D5A194AB189F/image-size/large?v=v2&amp;amp;px=999" role="button" title="2018-09-17_16-41-42.png" alt="2018-09-17_16-41-42.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 17 Sep 2018 14:44:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231090#M66350</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-09-17T14:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption just some users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231091#M66351</link>
      <description>&lt;P&gt;Thank you Kiwi. I think i didn't explain myself well haha.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know i&amp;nbsp;can define some source users, i already have some of then. My question is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If for example i want the users of an OU of my AD and they are 200 users, ¿Do i have to put those 200 users manually? Because i think i can't use groups from my domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in the future i would like to open it for the rest of users&amp;nbsp; of my company and the problem is that if i do it with subnets, i'll have devices without the CA cert and those will have problems probably.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, thank you for help!!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 15:06:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231091#M66351</guid>
      <dc:creator>PedroPablo</dc:creator>
      <dc:date>2018-09-17T15:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption just some users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231142#M66362</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;While the PAN cannot do an OU per se, it can do groups, so you could potentially just create an AD group and use it. Also as you can see in the screen shot above is to use Source IP's and/or Source Zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 20:47:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231142#M66362</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-17T20:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption just some users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231183#M66382</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/95192"&gt;@PedroPablo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The screenshot might be misleading ... "Source users" doesn't mean you have to add each user&amp;nbsp; individually &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As Otakar mentioned you can create AD groups and use those in your decryption policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 18 Sep 2018 07:18:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231183#M66382</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-09-18T07:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption just some users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231185#M66384</link>
      <description>&lt;P&gt;Thank you guys for your help.&amp;nbsp;For example, could i use the group of domain users?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The thing is when i want for example to use an user in that decryption policy, i go to "Source User" and i type the first two letters of the user name and i get a list of a bunch of users with those letters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But i've never seen the name of a group. So i don't know if just putting the name of the group is gonna work. Sorry if i'm not explaining myself really well. Thank you for your patience!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 07:49:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231185#M66384</guid>
      <dc:creator>PedroPablo</dc:creator>
      <dc:date>2018-09-18T07:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption just some users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231208#M66389</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/95192"&gt;@PedroPablo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This can help you I think &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Check-Users-in-LDAP-Groups/ta-p/59028" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Check-Users-in-LDAP-Groups/ta-p/59028&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you correctly configure Group Mappings at Device &amp;gt; User Identification &amp;gt; Group Mapping Settings ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 18 Sep 2018 12:03:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231208#M66389</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-09-18T12:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption just some users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231212#M66391</link>
      <description>&lt;P&gt;It helped me a lot&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;! Thank you so much for your help!&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;thank you too!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That was my problem. I had configured correctly the Group Mapping but i had to include the group i wanted in the "Group Include List".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a nice day guys!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 13:20:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231212#M66391</guid>
      <dc:creator>PedroPablo</dc:creator>
      <dc:date>2018-09-18T13:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption just some users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231216#M66392</link>
      <description>&lt;P&gt;Glad you got it working!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 13:42:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-just-some-users/m-p/231216#M66392</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-18T13:42:32Z</dc:date>
    </item>
  </channel>
</rss>

