<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Block / Continue on SSL - doesn't continue, page just refreshes. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-block-continue-on-ssl-doesn-t-continue-page-just-refreshes/m-p/366976#M88778</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The idea of creating certificates locally in order to server up a response page without decryption, is a hit and miss, based on how the individual website is seen/received by the PANW FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is surrounding why you would not start to implement decryption for Internet based traffic.&lt;/P&gt;
&lt;P&gt;Is there a question/concern that prevents you from want to implement it.&lt;/P&gt;
&lt;P&gt;About 80% of websites are SSL encrypted, that means AV, spyware, and vulnerabilities, ransomeware can enter your network, because you are not decrypting.&lt;/P&gt;
&lt;P&gt;Your users can/probably are exfiltrating data out of the network, providing loss of intellectual property, credit card, PII, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is recommended that ALL companies start to deploy certs and roll them out to their users.&lt;/P&gt;
&lt;P&gt;You have already done a large amount of work already... just need to get the certs from the FW (or the root CA) deployed to your users.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there hesitations, and how can we in Live, assist you and your company through making these very important modifications to your configuration?&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2020 01:37:17 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2020-12-03T01:37:17Z</dc:date>
    <item>
      <title>URL Block / Continue on SSL - doesn't continue, page just refreshes.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-block-continue-on-ssl-doesn-t-continue-page-just-refreshes/m-p/346464#M86520</link>
      <description>&lt;P&gt;I have a "continue" policy set on newly registered domains category.&amp;nbsp; If I visit a site with https I see the continue page but upon clicking continue the block page just refreshes (the guid in the address bar changes).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I visit the site without SSL, the block page appears, and clicking continue will correctly take me to the site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What have I misconfigured?&amp;nbsp; I do not have SSL Decryption set up in general and did follow the KB article "How to Serve a URL Response Page Over an HTTPS Session Without SSL Decryption" and I am not getting any sort of cert error.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 19:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-block-continue-on-ssl-doesn-t-continue-page-just-refreshes/m-p/346464#M86520</guid>
      <dc:creator>cenders</dc:creator>
      <dc:date>2020-09-02T19:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: URL Block / Continue on SSL - doesn't continue, page just refreshes.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-block-continue-on-ssl-doesn-t-continue-page-just-refreshes/m-p/366976#M88778</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The idea of creating certificates locally in order to server up a response page without decryption, is a hit and miss, based on how the individual website is seen/received by the PANW FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is surrounding why you would not start to implement decryption for Internet based traffic.&lt;/P&gt;
&lt;P&gt;Is there a question/concern that prevents you from want to implement it.&lt;/P&gt;
&lt;P&gt;About 80% of websites are SSL encrypted, that means AV, spyware, and vulnerabilities, ransomeware can enter your network, because you are not decrypting.&lt;/P&gt;
&lt;P&gt;Your users can/probably are exfiltrating data out of the network, providing loss of intellectual property, credit card, PII, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is recommended that ALL companies start to deploy certs and roll them out to their users.&lt;/P&gt;
&lt;P&gt;You have already done a large amount of work already... just need to get the certs from the FW (or the root CA) deployed to your users.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there hesitations, and how can we in Live, assist you and your company through making these very important modifications to your configuration?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 01:37:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-block-continue-on-ssl-doesn-t-continue-page-just-refreshes/m-p/366976#M88778</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-12-03T01:37:17Z</dc:date>
    </item>
  </channel>
</rss>

