<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption not working with Policy based forwarding in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247369#M70380</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83148"&gt;@Shuaib_Khalid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The SSL error implies that the client is successfully getting decrypted but they aren't trusting the "Forward Trust" certificate that the firewall is presenting it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q1 - Where did you obtain the certificate from? Was it from Active Directory Certificate Server (or PKI equivalent) or self-signed on the firewall?&lt;/P&gt;&lt;P&gt;Q2 If from PKI, is the machine part of the domain, and have you pushed out this cert to "Trusted Root Certification Authorities" folder via GPO?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If self-signed, the certificate needs to be installed again in the Trusted Root Certification Authorities folder for the local machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q3 - If the certificate marked as CA? Certificate authority?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jan 2019 14:37:51 GMT</pubDate>
    <dc:creator>LukeBullimore</dc:creator>
    <dc:date>2019-01-24T14:37:51Z</dc:date>
    <item>
      <title>SSL Decryption not working with Policy based forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247333#M70378</link>
      <description>&lt;P&gt;I have configured SSL decryption with one ISP which is configured via default route and it is working fine. I have another ISP and I configured to forward internet traffic from particular endpoints (same trust zone) to 2nd ISP, for this purpose i created NAT and&amp;nbsp; a PBF rule&amp;nbsp;for those particular endpoints, scenario was working fine till now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want decrypt the outgoing internet traffic of 2nd ISP users as well, i created another decryption rule for those users by mentioning destination zone of 2nd ISP, but there is SSL error on end points.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me in this regard.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 12:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247333#M70378</guid>
      <dc:creator>Shuaib_Khalid</dc:creator>
      <dc:date>2019-01-24T12:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working with Policy based forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247369#M70380</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83148"&gt;@Shuaib_Khalid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The SSL error implies that the client is successfully getting decrypted but they aren't trusting the "Forward Trust" certificate that the firewall is presenting it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q1 - Where did you obtain the certificate from? Was it from Active Directory Certificate Server (or PKI equivalent) or self-signed on the firewall?&lt;/P&gt;&lt;P&gt;Q2 If from PKI, is the machine part of the domain, and have you pushed out this cert to "Trusted Root Certification Authorities" folder via GPO?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If self-signed, the certificate needs to be installed again in the Trusted Root Certification Authorities folder for the local machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q3 - If the certificate marked as CA? Certificate authority?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 14:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247369#M70380</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-01-24T14:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working with Policy based forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247579#M70428</link>
      <description>&lt;P&gt;Hi Luke,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank for responding on the query, below are answers of your questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q1 - Where did you obtain the certificate from? Was it from Active Directory Certificate Server (or PKI equivalent) or self-signed on the firewall?&lt;/P&gt;&lt;P&gt;Ans: Certificate is self singed generated from Palo Alto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q2 If from PKI, is the machine part of the domain, and have you pushed out this cert to "Trusted Root Certification Authorities" folder via GPO?&lt;/P&gt;&lt;P&gt;Ans: I have manually imported the certificate on testing machines in Trusted Root of all browsers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If self-signed, the certificate needs to be installed again in the Trusted Root Certification Authorities folder for the local machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q3 - If the certificate marked as CA? Certificate authority?&lt;/P&gt;&lt;P&gt;Ans: Yes, the certificate is marked as CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i put testing machin on ISP 1 there no certificate error, decryption is succesfull and i got proper application detection but when i put the same machine on ISP 2 it gives SSL error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some Important points:&lt;/P&gt;&lt;P&gt;I have one SSL certificate on the firewall and two decryption policies for ISP1 and ISP2 users.&lt;/P&gt;&lt;P&gt;ISP1 is configured with default route while traffic is forwarding to ISP via PBF&lt;/P&gt;&lt;P&gt;Both ISPs are in different untrust zones&lt;/P&gt;&lt;P&gt;Source Zone is same&lt;/P&gt;&lt;P&gt;If i disable SSL decryption policy for ISP2 then browsing was succesfull&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any guess??&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 12:58:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247579#M70428</guid>
      <dc:creator>Shuaib_Khalid</dc:creator>
      <dc:date>2019-01-25T12:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working with Policy based forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247581#M70429</link>
      <description>&lt;P&gt;Can you take a screenshot of the certificate message you are getting? Is it something like Unknown Certificate authority?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you then click the padlock in chrome -&amp;gt; certificate -&amp;gt; certification path. Are any certificate(s) in this path showing as red X?&lt;BR /&gt;&amp;nbsp;That would mean they are not imported into the Trusted Root CA Store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF should not break forward proxy.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 13:09:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247581#M70429</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-01-25T13:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working with Policy based forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247786#M70500</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Chrome_error.JPG" style="width: 676px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18471i411568560EB7D005/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Chrome_error.JPG" alt="Chrome_error.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Chrome_error1.JPG" style="width: 431px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18470iD36833F83C46342C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Chrome_error1.JPG" alt="Chrome_error1.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Firefox_error.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18473iFDB11672340FC4F9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Firefox_error.JPG" alt="Firefox_error.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Firefox_error1.JPG" style="width: 625px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18472iA297A664E257759C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Firefox_error1.JPG" alt="Firefox_error1.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="traffic_logs(Successfull decryption).JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18474iF7DFCC2F5169D030/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="traffic_logs(Successfull decryption).JPG" alt="traffic_logs(Successfull decryption).JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="traffic_logs(Unsuccessfull decryption).JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18475i3256634CEAE5F35C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="traffic_logs(Unsuccessfull decryption).JPG" alt="traffic_logs(Unsuccessfull decryption).JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 14:23:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247786#M70500</guid>
      <dc:creator>Shuaib_Khalid</dc:creator>
      <dc:date>2019-01-28T14:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working with Policy based forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247787#M70501</link>
      <description>&lt;P&gt;Hi Luke,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appologize for delayed response, i have attached some screenshots in above message mentioning the SSL error in Chrome &amp;amp; Firefox, i have also attached traffic logs for ISP1 (Succesfull Decryption) and ISP2 (Unsuccesfull Decryption).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: Non SSL sites are working fine on ISP2.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 14:26:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247787#M70501</guid>
      <dc:creator>Shuaib_Khalid</dc:creator>
      <dc:date>2019-01-28T14:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working with Policy based forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247788#M70502</link>
      <description>&lt;P&gt;What do you see if anything, when you click on "View Certificate" ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards ... Leslie&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 14:28:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247788#M70502</guid>
      <dc:creator>LeslieGomba</dc:creator>
      <dc:date>2019-01-28T14:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption not working with Policy based forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247791#M70505</link>
      <description>&lt;P&gt;Nothing happens on clicking "View Certificate".&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 15:00:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-not-working-with-policy-based-forwarding/m-p/247791#M70505</guid>
      <dc:creator>Shuaib_Khalid</dc:creator>
      <dc:date>2019-01-28T15:00:15Z</dc:date>
    </item>
  </channel>
</rss>

