<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with URL Category in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243351#M69593</link>
    <description>&lt;P&gt;It still knows because it can read domain and SNI information from the certificate but it can't see exact url visited.&lt;/P&gt;&lt;P&gt;For example Google services use *.google.com&lt;/P&gt;&lt;P&gt;So you don't know if user went to search, maps or some other service.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Dec 2018 17:03:23 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2018-12-14T17:03:23Z</dc:date>
    <item>
      <title>Issue with URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243340#M69590</link>
      <description>&lt;P&gt;We have just setup SSL decryption and added custom response pages on our firewall.&amp;nbsp; We have a custom filter for shopping sites and the category is set to alert, if a user is a member of an AD group associated with this filter it works fine.&amp;nbsp; We decided in our fall back filter to set the category to continue which would display a message and allow the user to click continue to the site.&amp;nbsp; The problem is any shopping site visited the user gets a generic page cannot be displayed in their browser, decryption is disabled for the shopping category but cannot determine why this is failing when other categories which are set to continue seem to work ok.&amp;nbsp; Any one have any ideas why this one category is not working correctly?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 15:38:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243340#M69590</guid>
      <dc:creator>AlertsUser</dc:creator>
      <dc:date>2018-12-14T15:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243348#M69591</link>
      <description>&lt;P&gt;Issue is that if traffic is HTTP then it goes like this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SYN&lt;/P&gt;&lt;P&gt;SYN ACK&lt;/P&gt;&lt;P&gt;ACK&lt;/P&gt;&lt;P&gt;HTTP GET&lt;/P&gt;&lt;P&gt;Response containing website (Palo can intercept and send back continue page)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case on HTTPS&lt;/P&gt;&lt;P&gt;SYN&lt;/P&gt;&lt;P&gt;SYN ACK&lt;/P&gt;&lt;P&gt;ACK&lt;/P&gt;&lt;P&gt;Client Hello&lt;/P&gt;&lt;P&gt;Server Hello&lt;/P&gt;&lt;P&gt;Server Certificate&lt;/P&gt;&lt;P&gt;HTTP GET (encrypted)&lt;/P&gt;&lt;P&gt;Response containing website (encrypted, Palo can't see this and cannot intercept)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 16:00:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243348#M69591</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-12-14T16:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243350#M69592</link>
      <description>&lt;P&gt;Yep of course seeing your explaination makes it clear, if the site is not decrypted then the firewall does not known what category the website is under and therefore does not display the response page, thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 16:33:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243350#M69592</guid>
      <dc:creator>AlertsUser</dc:creator>
      <dc:date>2018-12-14T16:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243351#M69593</link>
      <description>&lt;P&gt;It still knows because it can read domain and SNI information from the certificate but it can't see exact url visited.&lt;/P&gt;&lt;P&gt;For example Google services use *.google.com&lt;/P&gt;&lt;P&gt;So you don't know if user went to search, maps or some other service.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 17:03:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243351#M69593</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-12-14T17:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with URL Category</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243378#M69596</link>
      <description>&lt;P&gt;Great info Raido&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 19:14:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-url-category/m-p/243378#M69596</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-12-14T19:14:19Z</dc:date>
    </item>
  </channel>
</rss>

