<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Categories and SSL Decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360772#M88132</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/161315"&gt;@KAckerman12&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For me it is working fine when i access that website it does not get decrypted.&lt;/P&gt;
&lt;P&gt;I also see it categorize as financial first then low risk.&lt;/P&gt;
&lt;P&gt;Seems it is by design as per my understanding.&lt;/P&gt;
&lt;P&gt;Make sure under decryption policy for financial services under options action is set to no decrypt.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2020 21:09:50 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2020-11-04T21:09:50Z</dc:date>
    <item>
      <title>URL Categories and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360759#M88131</link>
      <description>&lt;P&gt;I'm having an issue with URL Categories and SSL Decryption. I have two decryption policies; the first is a no-decrypt policy for URL Categories matching "financial-services" and "healthcare-and-medicine," and the second policy is a decrypt-all for service-https. The second rule is working great and decrypting traffic as expected, however, the first rule is not working. If I visit a financial site (discover.com, chase.com, etc) the site is getting decrypted. The log shows the site as matching against "low-risk" instead of "financial-services." This happens for most sites and is not limited to the examples provided.&amp;nbsp; If I visit &lt;A href="https://urlfiltering.paloaltonetworks.com/" target="_blank"&gt;https://urlfiltering.paloaltonetworks.com/&lt;/A&gt; it shows discover.com gets categorized as financial-services first, then low-risk. What can I do to ensure the firewall categorizes these sites as financial-services instead of low-risk so that they do not get decrypted?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 20:38:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360759#M88131</guid>
      <dc:creator>KAckerman12</dc:creator>
      <dc:date>2020-11-04T20:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categories and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360772#M88132</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/161315"&gt;@KAckerman12&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For me it is working fine when i access that website it does not get decrypted.&lt;/P&gt;
&lt;P&gt;I also see it categorize as financial first then low risk.&lt;/P&gt;
&lt;P&gt;Seems it is by design as per my understanding.&lt;/P&gt;
&lt;P&gt;Make sure under decryption policy for financial services under options action is set to no decrypt.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 21:09:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360772#M88132</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-11-04T21:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categories and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360778#M88135</link>
      <description>&lt;P&gt;The policy was in place with no-decrypt, but that wasn't the issue. I was able to solve this by adding these categories directly to the policy.&lt;/P&gt;&lt;P&gt;The problem occurred when using a custom URL Category object where I added financial-services and health-and-medicine. I then applied the custom object to the no-decrypt policy, but it failed to appropriately reference the custom object, and sites were still being decrypted.&amp;nbsp; Instead of adding the custom object, I added these categories directly to the policy, and since then it has worked fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the quick response!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 22:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360778#M88135</guid>
      <dc:creator>KAckerman12</dc:creator>
      <dc:date>2020-11-04T22:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categories and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360780#M88136</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/161315"&gt;@KAckerman12&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I my config i was using these default categories not the custom one.&lt;/P&gt;
&lt;P&gt;I never tried custom categories as PA already have those built in so no use of creating custom categories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I only used custom categories for single urls not for whole url category.&lt;/P&gt;
&lt;P&gt;Thanks for updating the community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 23:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360780#M88136</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-11-04T23:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categories and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360797#M88138</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/161315"&gt;@KAckerman12&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That definitely sounds like a bug, and one that I can't duplicate on 9.1.5. What version of PAN-OS are you running currently?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 02:04:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360797#M88138</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-11-05T02:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categories and SSL Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360884#M88153</link>
      <description>&lt;P&gt;I should clarify; I didn't create a custom category, but rather created a group for these categories. Objects&amp;gt;Custom Objects&amp;gt;URL Category&amp;gt;Add&amp;gt;Type 'Category Match'.&amp;nbsp; I added these categories into that custom object group, and applied the custom object group to the no-decrypt policy. However, the no-decrypt policy failed to reference the custom category group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently using version 9.0.9-h1&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 16:39:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categories-and-ssl-decryption/m-p/360884#M88153</guid>
      <dc:creator>KAckerman12</dc:creator>
      <dc:date>2020-11-05T16:39:43Z</dc:date>
    </item>
  </channel>
</rss>

