<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Server Response Inspection for HTTPS/VPN/Encrypted Protocols in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/server-response-inspection-for-https-vpn-encrypted-protocols/m-p/259601#M73594</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are experiencing slow/failed downloads and slow/failed file transfers over protocols like HTTPS, SSL, VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;like to hear some opinion regarding "Disable Server Response Inspection", does PAN actually inspect encrypted sessions even though there is no SSL Decryption configured?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For DSRI, usual deployments are Inbound traffic toward Public Facing server as per the documentation for trusted servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since there is no SSL decryption configured, would it be better to check the option "DSRI" for encrypted protocols such as HTTPS / SSL??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2019 11:55:51 GMT</pubDate>
    <dc:creator>williamhakai</dc:creator>
    <dc:date>2019-05-02T11:55:51Z</dc:date>
    <item>
      <title>Server Response Inspection for HTTPS/VPN/Encrypted Protocols</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-response-inspection-for-https-vpn-encrypted-protocols/m-p/259601#M73594</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are experiencing slow/failed downloads and slow/failed file transfers over protocols like HTTPS, SSL, VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;like to hear some opinion regarding "Disable Server Response Inspection", does PAN actually inspect encrypted sessions even though there is no SSL Decryption configured?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For DSRI, usual deployments are Inbound traffic toward Public Facing server as per the documentation for trusted servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since there is no SSL decryption configured, would it be better to check the option "DSRI" for encrypted protocols such as HTTPS / SSL??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 11:55:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-response-inspection-for-https-vpn-encrypted-protocols/m-p/259601#M73594</guid>
      <dc:creator>williamhakai</dc:creator>
      <dc:date>2019-05-02T11:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Server Response Inspection for HTTPS/VPN/Encrypted Protocols</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-response-inspection-for-https-vpn-encrypted-protocols/m-p/259619#M73597</link>
      <description>&lt;P&gt;if thewre is no ssl decryption, there will be minimal inspection so DISR my not have the desired effect&lt;/P&gt;
&lt;P&gt;have you checked if there's many renegotiation/handshakes taking place, or possibly fragmentation/duplicate packets at the TCP layer?&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 13:06:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-response-inspection-for-https-vpn-encrypted-protocols/m-p/259619#M73597</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-05-02T13:06:21Z</dc:date>
    </item>
  </channel>
</rss>

