<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block Page not always displayed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331800#M83963</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client should trust, the ssl certificate presented from firewall, Firefox keeps certificates on seperate store when importing proccess select all the checkboxes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other possible reasons are;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;there another device which is making ssl inspection between client and firewall, or between firewall and the destination server.&lt;/LI&gt;&lt;LI&gt;if firewall and clients are on different location maybe a mpls connection, routing problems coauses this error which i experienced before. SSL connection is sensitive to routing problems.&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Fri, 05 Jun 2020 07:01:56 GMT</pubDate>
    <dc:creator>upelister</dc:creator>
    <dc:date>2020-06-05T07:01:56Z</dc:date>
    <item>
      <title>Block Page not always displayed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331626#M83947</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the problem that for some URLs I get a block Page and for other URLs I get the "Error secure connection failed" Message.&lt;/P&gt;&lt;P&gt;Both responses have the same session end reason:&amp;nbsp;&lt;SPAN&gt;decrypt-cert-validation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As this happens regarding SSL connections I use a decryption Profile with checked:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Block sessions with expired certificates&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Block sessions with untrusted issuers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Block sessions with unknown certificate status&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Block sessions on certificate status check timeout&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried with Firefox and Chrome and got the explained result.&lt;/P&gt;&lt;P&gt;The Internet Explorer seems to always show the requested block page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone maybe explain why this is happening and maybe how I can for example get Firefox to always show the block page?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 14:24:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331626#M83947</guid>
      <dc:creator>Marc.Luecke</dc:creator>
      <dc:date>2020-06-04T14:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Block Page not always displayed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331654#M83950</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123063"&gt;@Marc.Luecke&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Do you utilize a web proxy at all on the browsers that aren't working as expected?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 16:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331654#M83950</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-04T16:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Block Page not always displayed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331800#M83963</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client should trust, the ssl certificate presented from firewall, Firefox keeps certificates on seperate store when importing proccess select all the checkboxes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other possible reasons are;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;there another device which is making ssl inspection between client and firewall, or between firewall and the destination server.&lt;/LI&gt;&lt;LI&gt;if firewall and clients are on different location maybe a mpls connection, routing problems coauses this error which i experienced before. SSL connection is sensitive to routing problems.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 05 Jun 2020 07:01:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331800#M83963</guid>
      <dc:creator>upelister</dc:creator>
      <dc:date>2020-06-05T07:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Block Page not always displayed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331834#M83969</link>
      <description>&lt;P&gt;Unfortunately there is no web proxy used.&lt;/P&gt;&lt;P&gt;But thanks for the hint &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 09:08:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331834#M83969</guid>
      <dc:creator>Marc.Luecke</dc:creator>
      <dc:date>2020-06-05T09:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Block Page not always displayed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331837#M83970</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the Certificate is installed to the trusted certificate store of Firefox.&lt;/P&gt;&lt;P&gt;There are no other devices installed between client and FW or FW and destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to inform myself about the locations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please don't misunderstand the issue as this is about that, for the same session end reason, I get two different outputs. Sometimes the Error message, sometimes the block page and I would like to always get the block page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems to work fine in the Internet Explorer, so I am kind of confused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&amp;nbsp;I have check the "&lt;SPAN&gt;Strip ALPN" Option in the Decryption Profile and it works for now. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Maybe because now HTTP1 is used?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it possible that the NGFW has problems with HTTP2 ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Marc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 09:35:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-page-not-always-displayed/m-p/331837#M83970</guid>
      <dc:creator>Marc.Luecke</dc:creator>
      <dc:date>2020-06-05T09:35:17Z</dc:date>
    </item>
  </channel>
</rss>

