<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I have question with SSL decryption. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/i-have-question-with-ssl-decryption/m-p/271357#M74816</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Was decryption working prior to the HA change? If not then the policies are incorrect because of decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I.E. the firewall will detect ssl over tcp/443 then decrypt it, the traffic is then reinspected and is determined to be web-browsing over tcp/443 instead of tcp/80 so it breaks unless you allow web-browsing over tcp/443.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmyCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmyCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Heop that helps.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jun 2019 14:35:09 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-06-19T14:35:09Z</dc:date>
    <item>
      <title>I have question with SSL decryption.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-have-question-with-ssl-decryption/m-p/271191#M74802</link>
      <description>&lt;P&gt;Hi there.&lt;/P&gt;&lt;P&gt;Few days ago, I 'd changed one of my client's F/W .&lt;/P&gt;&lt;P&gt;Everything was okay but decryption wasn't working.&lt;/P&gt;&lt;P&gt;After few times, I found out what problem was causing that issues.&lt;BR /&gt;(added decryption profile and changed policies (service: application-default -&amp;gt; any)&lt;BR /&gt;But I don't know why do I have to add profile and changed service. So Please let me know why it has to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there is information :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before :&lt;BR /&gt;Model : 3050&lt;BR /&gt;Version : 7.1.7&lt;BR /&gt;mode: VW&lt;BR /&gt;HA(A-A)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After :&lt;BR /&gt;Model : 3260&lt;BR /&gt;Version : 8.1.7&lt;BR /&gt;mode : L3&lt;BR /&gt;HA : A-P&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 06:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-have-question-with-ssl-decryption/m-p/271191#M74802</guid>
      <dc:creator>ninecross</dc:creator>
      <dc:date>2019-06-19T06:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: I have question with SSL decryption.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-have-question-with-ssl-decryption/m-p/271357#M74816</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Was decryption working prior to the HA change? If not then the policies are incorrect because of decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I.E. the firewall will detect ssl over tcp/443 then decrypt it, the traffic is then reinspected and is determined to be web-browsing over tcp/443 instead of tcp/80 so it breaks unless you allow web-browsing over tcp/443.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmyCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmyCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Heop that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 14:35:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-have-question-with-ssl-decryption/m-p/271357#M74816</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-06-19T14:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: I have question with SSL decryption.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-have-question-with-ssl-decryption/m-p/271920#M74874</link>
      <description>&lt;P&gt;I think I may see/understand your situation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Prior to 9.x software, the PANOS software did not include secured ports in its AppID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt;When SSL:443 traffic is decrypted, the application becomes web-browsing:443 (port does not change)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;because 443 is not app-default for web-browsing, then it is not longer a match.&lt;/P&gt;&lt;P&gt;If policy was app-default then you would need to change web-browsing to allow 80, 8080, and 443, or change to service any.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;maybe this is your issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 21:30:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-have-question-with-ssl-decryption/m-p/271920#M74874</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-06-20T21:30:23Z</dc:date>
    </item>
  </channel>
</rss>

