<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Do I need SSL decryption to turned ON for Wildfire deployment ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277112#M75422</link>
    <description>&lt;P&gt;Can Wildfire engine detect &amp;amp; identify zero day or known threat if SSL decrption feature is off in Palo Alto firewall ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WildFire can discover zero-day malware in web traffic (HTTP/HTTPS), email protocols (SMTP, IMAP, and POP), and FTP traffic and can quickly generate signatures to identify and protect against future infections from the malware it discovers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But how it detects file types, malicious behaviour for SSL encrypted traffic ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jul 2019 21:01:55 GMT</pubDate>
    <dc:creator>PS007</dc:creator>
    <dc:date>2019-07-17T21:01:55Z</dc:date>
    <item>
      <title>Do I need SSL decryption to turned ON for Wildfire deployment ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277112#M75422</link>
      <description>&lt;P&gt;Can Wildfire engine detect &amp;amp; identify zero day or known threat if SSL decrption feature is off in Palo Alto firewall ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WildFire can discover zero-day malware in web traffic (HTTP/HTTPS), email protocols (SMTP, IMAP, and POP), and FTP traffic and can quickly generate signatures to identify and protect against future infections from the malware it discovers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But how it detects file types, malicious behaviour for SSL encrypted traffic ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 21:01:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277112#M75422</guid>
      <dc:creator>PS007</dc:creator>
      <dc:date>2019-07-17T21:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need SSL decryption to turned ON for Wildfire deployment ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277212#M75430</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/115091"&gt;@PS007&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You need SSL Decryption to get the full benefit of WildFire for encrypted traffic, as you would expect. If you don't have visability into the traffic WildFire won't be able to identify the content being downloaded and therefore isn't able to fully protect your environment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 03:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277212#M75430</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-18T03:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need SSL decryption to turned ON for Wildfire deployment ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277455#M75458</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;my organization dont want to turn SSL decryption ON due to user privacy issues. What other benefits I can get from WF ? How about email/ftp or any other traffic ?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 14:25:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277455#M75458</guid>
      <dc:creator>PS007</dc:creator>
      <dc:date>2019-07-18T14:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need SSL decryption to turned ON for Wildfire deployment ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277471#M75461</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/115091"&gt;@PS007&lt;/a&gt;&amp;nbsp;, please keep in mind that more and more applications and sites are being encrypted to be more secure.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, if you are not decrypting SSL, then you are missing out on a big piece of the puzzle.&lt;/P&gt;
&lt;P&gt;When you setup the decryption policy, you normally exclude Banking, Hospital/medical, and similar categories to respect personal privacy.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 14:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277471#M75461</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2019-07-18T14:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need SSL decryption to turned ON for Wildfire deployment ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277487#M75465</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/115091"&gt;@PS007&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So if you don't decrypt traffic WildFire is only able to act on what it can actually see crossing the firewall, which at that point would be any unencrypted traffic. So while FTP traffic would get inspected SFTP would not, likewise HTTP downloads would be inspected but HTTPS downloads would not be. There is still a lot of benefit in catching the "low-hanging fruit" utilizing WildFire in a network while not utilizing SSL Decryption for external traffic. That being said, more and more traffic is switching to encrypted by default, so the effective percentage of your analyzed traffic would continue to go down as the percentage of your encrypted traffic goes up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would argue that with you falling under GDPR you actually have even&amp;nbsp;&lt;EM&gt;more&lt;/EM&gt; of a reason to gain insight into your traffic patterns, not less. As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;mentioned you can exclude any category or domain that you don't want decrypted with ease, but choosing to go without decryption all-together is relatively risky if your org actually gets breached and would have to report it. IE: The cost of being fined under GDPR because customer or employee information was potentially exported/accessed under a network breach would be rather massive; and unless you decrypt traffic hitting a public resource you host on your network (inbound decryption) you don't really have that big of a GDPR risk with the right retentention policies in place.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 16:21:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-need-ssl-decryption-to-turned-on-for-wildfire-deployment/m-p/277487#M75465</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-18T16:21:45Z</dc:date>
    </item>
  </channel>
</rss>

