<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block websites when using VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253079#M71909</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="traffic.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19043iE449F75C706A4303/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="traffic.JPG" alt="traffic.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It says decrypted. The problem is that users need to use SoftEther VPN to access certain website. But using this VPN client can bypass all our security rule in place. May be we can find another way to access the website without using VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 10:29:07 GMT</pubDate>
    <dc:creator>nredaj</dc:creator>
    <dc:date>2019-03-11T10:29:07Z</dc:date>
    <item>
      <title>Block websites when using VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253057#M71902</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Some users started to use SoftEther VPN client on our company which allows them to bypass URL Filtering policy. How can we allow them to use VPN client but still allow or block access to certain websites. We already implemented SSL decryption rule but it is not working when they are using SoftEther VPN.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:02:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253057#M71902</guid>
      <dc:creator>nredaj</dc:creator>
      <dc:date>2019-03-11T06:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Block websites when using VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253067#M71905</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108474"&gt;@nredaj&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is decryption working ?&lt;/P&gt;
&lt;P&gt;How is the traffic identified by the firewall ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:08:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253067#M71905</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-03-11T09:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Block websites when using VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253076#M71907</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Decyption is working. Based on monitoring logs, when using VPN client, all traffic are identied as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application: SSL&lt;/P&gt;&lt;P&gt;IP Protocol: TCP&lt;/P&gt;&lt;P&gt;Port: 443&lt;/P&gt;&lt;P&gt;Category: computer-and-internet-info&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:56:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253076#M71907</guid>
      <dc:creator>nredaj</dc:creator>
      <dc:date>2019-03-11T09:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Block websites when using VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253077#M71908</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108474"&gt;@nredaj&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How is decryption working ?&lt;/P&gt;
&lt;P&gt;If the application is identified as SSL then decryption isn't working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that on some scenarios decryption is impossible ... &lt;SPAN&gt;&lt;SPAN style="text-align: justify;"&gt;for example when unsupported protocols or ciphers are used or with&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN style="text-align: justify;"&gt; certificate pinning for example.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:11:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253077#M71908</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-03-11T10:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Block websites when using VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253079#M71909</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="traffic.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19043iE449F75C706A4303/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="traffic.JPG" alt="traffic.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It says decrypted. The problem is that users need to use SoftEther VPN to access certain website. But using this VPN client can bypass all our security rule in place. May be we can find another way to access the website without using VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:29:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253079#M71909</guid>
      <dc:creator>nredaj</dc:creator>
      <dc:date>2019-03-11T10:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Block websites when using VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253085#M71910</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108474"&gt;@nredaj&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might be hitting this which could explain why a decrypted session is still showing up as SSL :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cle8CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cle8CAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you checked with support already ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:49:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253085#M71910</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-03-11T10:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Block websites when using VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253114#M71921</link>
      <description>&lt;P&gt;Hmm, I think the ssl decryption here will not be as helpful as usual.&amp;nbsp;&amp;nbsp; you will only decrypt the outer wrapper (the actual tunnel)&amp;nbsp;any ssl packets running through the&amp;nbsp;tunnel will not be decrypted as negotiation for these will have taken place end to end via the tunnel, not the palo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:16:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253114#M71921</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-11T16:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Block websites when using VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253118#M71924</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108474"&gt;@nredaj&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;in this case. Decrypting this traffic isn't going to give you much information and won't allow you to actually perform URL FIltering; this is actually the exact reason VPNs are recommended on untrusted networks, the network operator can't decrypt enough of the traffic to actually see anything useful.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:23:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253118#M71924</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-03-11T18:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Block websites when using VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253268#M71938</link>
      <description>&lt;P&gt;I understand that this could be out of Palo Alto's FW scope.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a bit frustrating. Configuring static route in client side (windows OS) could have solve this issue but the website they're accessing is going thru CDN which cause IP address to change from time to time. Probable solution may be work out with SoftEther VPN configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you guys for all your inputs.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:56:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-websites-when-using-vpn/m-p/253268#M71938</guid>
      <dc:creator>nredaj</dc:creator>
      <dc:date>2019-03-12T07:56:27Z</dc:date>
    </item>
  </channel>
</rss>

