<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TLS 1.3 Encrypted SNI No-Decrypt URL  Categories in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tls-1-3-encrypted-sni-no-decrypt-url-categories/m-p/364532#M88479</link>
    <description>&lt;P&gt;Thank you for the reply!&amp;nbsp; Always good to hear from you.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering about the effectiveness of URL categories that are not decrypted on the firewall in a TLS1.3 world.&amp;nbsp; Do they become worthless?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Found the below link, but it still doesn't give a lot of info on the tls1.3 encrypted SNI.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClzlCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClzlCAC&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Nov 2020 18:08:50 GMT</pubDate>
    <dc:creator>Sec101</dc:creator>
    <dc:date>2020-11-20T18:08:50Z</dc:date>
    <item>
      <title>TLS 1.3 Encrypted SNI No-Decrypt URL  Categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tls-1-3-encrypted-sni-no-decrypt-url-categories/m-p/364238#M88458</link>
      <description>&lt;P&gt;In non decrypted tls 1.3 traffic, how is the firewall in 10.0 seeing the URL that a user requests and how is it enforcing that category?&amp;nbsp; I've read that tls1.3 encrypts the SNI field, which from my understanding, is the primary way the palo firewalls read and implement URL categories on non-decrypted traffic.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we don't decrypt on certain traffic (ex. financial), and that traffic is tls1.3, how is the firewall seeing a destination, other than an IP address, and how is it trying to utilize what it sees to a URL category?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read below, but still a bit foggy on this, as would this break URL categories period for non-decrypted traffic?&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/url-filtering-tls-1-3-website/m-p/244821#M69839" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/url-filtering-tls-1-3-website/m-p/244821#M69839&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 18:45:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tls-1-3-encrypted-sni-no-decrypt-url-categories/m-p/364238#M88458</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-11-19T18:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: TLS 1.3 Encrypted SNI No-Decrypt URL  Categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tls-1-3-encrypted-sni-no-decrypt-url-categories/m-p/364428#M88468</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/157358"&gt;@Sec101&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;TLSv1.3&amp;nbsp;&lt;EM&gt;supports&amp;nbsp;&lt;/EM&gt;encrypting the SNI field, but there's additional work that needs to be done to do so and a lot of sites aren't doing so at this time. For sites that choose to encrypt the SNI field, I imagine that the traffic is simply decrypted until the firewall can see what the site actually is and then it stops for the remainder of the established session. I could be wrong on that, but that's about as far as you could handle that situation as far as TLSv1.3 with encrypted SNI is concerned. I might have to lab this up this weekend to see exactly how that functions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 04:58:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tls-1-3-encrypted-sni-no-decrypt-url-categories/m-p/364428#M88468</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-11-20T04:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: TLS 1.3 Encrypted SNI No-Decrypt URL  Categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tls-1-3-encrypted-sni-no-decrypt-url-categories/m-p/364532#M88479</link>
      <description>&lt;P&gt;Thank you for the reply!&amp;nbsp; Always good to hear from you.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering about the effectiveness of URL categories that are not decrypted on the firewall in a TLS1.3 world.&amp;nbsp; Do they become worthless?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Found the below link, but it still doesn't give a lot of info on the tls1.3 encrypted SNI.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClzlCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClzlCAC&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 18:08:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tls-1-3-encrypted-sni-no-decrypt-url-categories/m-p/364532#M88479</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-11-20T18:08:50Z</dc:date>
    </item>
  </channel>
</rss>

