<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 'proxy decrypt failure' in session detail  even though no ssl decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239122#M68491</link>
    <description>&lt;P&gt;seems it was denying&amp;nbsp; on port 80 and some destination ips.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Allowed the port 80 and those destination ips it was good then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;strange the cli gives error&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;tracker stage firewall : proxy decrypt failure&lt;/PRE&gt;&lt;P&gt;even though traffic was not decrypted?&lt;/P&gt;&lt;P&gt;any thoughts on that?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Nov 2018 19:05:08 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2018-11-08T19:05:08Z</dc:date>
    <item>
      <title>'proxy decrypt failure' in session detail  even though no ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239093#M68484</link>
      <description>&lt;P&gt;CLI shows&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Session 33880958&lt;/P&gt;&lt;P&gt;c2s flow:&lt;BR /&gt;source: 10.29.32.146 [_DMZ]&lt;BR /&gt;dst: 65.55.163.76&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 59760 dport: 443&lt;BR /&gt;state: INIT type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;/P&gt;&lt;P&gt;s2c flow:&lt;BR /&gt;source: 65.55.163.76 [_EXT]&lt;BR /&gt;dst: 198.160.191.5&lt;BR /&gt;proto: 6&lt;BR /&gt;sport: 443 dport: 32999&lt;BR /&gt;state: INIT type: FLOW&lt;BR /&gt;src user: unknown&lt;BR /&gt;dst user: unknown&lt;BR /&gt;qos node: ae1.3741, qos member N/A Qid 0&lt;/P&gt;&lt;P&gt;DP : 1&lt;BR /&gt;index(local): : 326526&lt;BR /&gt;start time : Thu Nov 8 08:56:49 2018&lt;BR /&gt;timeout : 90 sec&lt;BR /&gt;total byte count(c2s) : 263&lt;BR /&gt;total byte count(s2c) : 128&lt;BR /&gt;layer7 packet count(c2s) : 3&lt;BR /&gt;layer7 packet count(s2c) : 2&lt;BR /&gt;vsys : vsys1&lt;BR /&gt;application : ssl&lt;BR /&gt;rule : interzone-default&lt;BR /&gt;session to be logged at end : True&lt;BR /&gt;session in session ager : False&lt;BR /&gt;session updated by HA peer : False&lt;BR /&gt;address/port translation : source&lt;BR /&gt;nat-rule :x.x.x&lt;BR /&gt;layer7 processing : enabled&lt;BR /&gt;URL filtering enabled : True&lt;BR /&gt;URL category : computer-and-internet-info&lt;BR /&gt;session via syn-cookies : False&lt;BR /&gt;session terminated on host : False&lt;BR /&gt;session traverses tunnel : False&lt;BR /&gt;captive portal session : False&lt;BR /&gt;ingress interface : ae1.3741&lt;BR /&gt;egress interface : ethernet1/13.4001&lt;BR /&gt;session QoS rule : N/A (class 4)&lt;BR /&gt;tracker stage firewall : proxy decrypt failure&lt;BR /&gt;end-reason : policy-deny&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rule is there to allow any app on port 443 tcp&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 16:23:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239093#M68484</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-11-08T16:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: 'proxy decrypt failure' in session detail  even though no ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239112#M68487</link>
      <description>&lt;P&gt;This is because&amp;nbsp;that session was denied for some reason in your security policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;Session 33880958&lt;/SPAN&gt;&lt;BR /&gt;...&lt;BR /&gt;tracker stage firewall : proxy decrypt failure
end-reason : &lt;FONT color="#FF0000"&gt;policy-deny&lt;/FONT&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFKCA0" target="_self"&gt;article&lt;/A&gt;&amp;nbsp;talks about the setup to ensure that a deny page is displayed (instead of a generic connection error). Your firewall has likely enabled that config, but was unable to display the page to the client. It could be as simple as the client not trusting the cert, which would make sense if you haven't set up decryption for your userbase.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 17:51:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239112#M68487</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-11-08T17:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: 'proxy decrypt failure' in session detail  even though no ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239122#M68491</link>
      <description>&lt;P&gt;seems it was denying&amp;nbsp; on port 80 and some destination ips.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Allowed the port 80 and those destination ips it was good then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;strange the cli gives error&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;tracker stage firewall : proxy decrypt failure&lt;/PRE&gt;&lt;P&gt;even though traffic was not decrypted?&lt;/P&gt;&lt;P&gt;any thoughts on that?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 19:05:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239122#M68491</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-11-08T19:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: 'proxy decrypt failure' in session detail  even though no ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239124#M68492</link>
      <description>&lt;P&gt;The session you pasted before was on port 443, so the port 80 allowance wouldn't have helped this session:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Session 33880958

        c2s flow:
                source: 10.29.32.146 [_DMZ]
                dst: 65.55.163.76
                proto: 6
                sport: 59760 &lt;FONT color="#FF0000"&gt;dport: 443&lt;/FONT&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I had to hazard a guess, it was probably the destination blocks that were in place. But since you do have a next-gen firewall, if you&amp;nbsp;&lt;STRONG&gt;are&lt;/STRONG&gt; seeing TLS(ssl) traffic on port 80, the firewall will still know it's TLS and will try to display the block page if it's denied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 19:15:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239124#M68492</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-11-08T19:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: 'proxy decrypt failure' in session detail  even though no ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239128#M68493</link>
      <description>&lt;P&gt;on Gui it is&amp;nbsp; showing as&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;type deny&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;action reset both&lt;/P&gt;&lt;P&gt;application ssl&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;session end reason policy deny&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 19:22:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-decrypt-failure-in-session-detail-even-though-no-ssl/m-p/239128#M68493</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-11-08T19:22:47Z</dc:date>
    </item>
  </channel>
</rss>

