<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decryption -  Without URL filtering license in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-without-url-filtering-license/m-p/253270#M71940</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I plan to put in place a SSL decryption rule to decrypt ssl traffic (SSL forward proxy). But I don't want decrypt traffic for several categories of website such as financial (bank website). I haven't the URL filtering license. I create a first rule "Do not decrypt" where I specify "Financial-services" in the URL category but when I test and reach a bank website, the certificate has been replaced by the certificate confiuged for decryption. Is-it because I haven't the URL filtering licenses ? And if I create on PA an URL category "Do-not-decrypt" with bank website used for the test and add this custom category in the rule "Do not decrypt", the website is not decrypted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know where I can find a list of bank site to be imported in the URL category created ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:02:33 GMT</pubDate>
    <dc:creator>CARRIERJerome</dc:creator>
    <dc:date>2019-03-12T09:02:33Z</dc:date>
    <item>
      <title>SSL Decryption -  Without URL filtering license</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-without-url-filtering-license/m-p/253270#M71940</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I plan to put in place a SSL decryption rule to decrypt ssl traffic (SSL forward proxy). But I don't want decrypt traffic for several categories of website such as financial (bank website). I haven't the URL filtering license. I create a first rule "Do not decrypt" where I specify "Financial-services" in the URL category but when I test and reach a bank website, the certificate has been replaced by the certificate confiuged for decryption. Is-it because I haven't the URL filtering licenses ? And if I create on PA an URL category "Do-not-decrypt" with bank website used for the test and add this custom category in the rule "Do not decrypt", the website is not decrypted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know where I can find a list of bank site to be imported in the URL category created ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:02:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-without-url-filtering-license/m-p/253270#M71940</guid>
      <dc:creator>CARRIERJerome</dc:creator>
      <dc:date>2019-03-12T09:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Without URL filtering license</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-without-url-filtering-license/m-p/253528#M71977</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84878"&gt;@CARRIERJerome&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, I am not a paloalto employee but this sounds like you should buy the URL filtering license ... or why don't you us the decryption opt-out response page to inform the users about the decryption and maybe also **bleep** should reach out to you when the access a banking website that is decrypted?&lt;/P&gt;&lt;P&gt;In general, I assume it could be difficult to find a list as keeping this list current is not that easy (which is why companys want you to pay money for this service &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&amp;nbsp; )&lt;/P&gt;&lt;P&gt;... or you simply start creating your own list &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:07:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-without-url-filtering-license/m-p/253528#M71977</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-03-13T00:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption -  Without URL filtering license</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-without-url-filtering-license/m-p/253533#M71979</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84878"&gt;@CARRIERJerome&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Agreed with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;, if you want to do something like this it would actually make more sense to actually purchase the URL Filtering license so you can actually get category updates.&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI, I actually use the URL categories and manually maintain a list of some of the smaller banks that I know my end-users utilize to ensure that we aren't decrypting banking information if we can at all help it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 02:15:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-without-url-filtering-license/m-p/253533#M71979</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-03-13T02:15:40Z</dc:date>
    </item>
  </channel>
</rss>

