<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decryption and Reddit Posting in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/382926#M89895</link>
    <description>&lt;P&gt;Last year I implemented a rule to allow users in my company access to the reddit.com site. It is in our company policy to disallow sharing messages on social media, so I implemented this rule with URL filtering (chat/messages/etc...) &lt;STRONG&gt;and&lt;/STRONG&gt; only allowing the appid "reddit-base", not "reddit-posting". This worked at the time, and has stopped functioning properly some time in the past year.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, users are still limited from messaging/chat/etc... but &lt;EM&gt;can&lt;/EM&gt; post comments and new threads on the site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This relates to SSL decryption as I was digging down the rabbit-hole and think that the "reddit-posting" appid has switched over to "web-browsing". I was wondering :&lt;/P&gt;&lt;P&gt;1. If I implement SSL decryption on reddit, will it pick up the "reddit-posting" appid again?&lt;/P&gt;&lt;P&gt;2. Why do I no longer see "reddit-posting" in my logs?&lt;/P&gt;&lt;P&gt;3. What can SSL decryption do--or can't do--to help me solve this issue?&lt;/P&gt;&lt;P&gt;4. Is this a more-so a question about how PA identifies appids for reddit?&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2021 18:19:00 GMT</pubDate>
    <dc:creator>nreynders</dc:creator>
    <dc:date>2021-01-29T18:19:00Z</dc:date>
    <item>
      <title>SSL Decryption and Reddit Posting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/382926#M89895</link>
      <description>&lt;P&gt;Last year I implemented a rule to allow users in my company access to the reddit.com site. It is in our company policy to disallow sharing messages on social media, so I implemented this rule with URL filtering (chat/messages/etc...) &lt;STRONG&gt;and&lt;/STRONG&gt; only allowing the appid "reddit-base", not "reddit-posting". This worked at the time, and has stopped functioning properly some time in the past year.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, users are still limited from messaging/chat/etc... but &lt;EM&gt;can&lt;/EM&gt; post comments and new threads on the site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This relates to SSL decryption as I was digging down the rabbit-hole and think that the "reddit-posting" appid has switched over to "web-browsing". I was wondering :&lt;/P&gt;&lt;P&gt;1. If I implement SSL decryption on reddit, will it pick up the "reddit-posting" appid again?&lt;/P&gt;&lt;P&gt;2. Why do I no longer see "reddit-posting" in my logs?&lt;/P&gt;&lt;P&gt;3. What can SSL decryption do--or can't do--to help me solve this issue?&lt;/P&gt;&lt;P&gt;4. Is this a more-so a question about how PA identifies appids for reddit?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 18:19:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/382926#M89895</guid>
      <dc:creator>nreynders</dc:creator>
      <dc:date>2021-01-29T18:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption and Reddit Posting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/382981#M89897</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/158125"&gt;@nreynders&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Last year I implemented a rule to allow users in my company access to the reddit.com site. It is in our company policy to disallow sharing messages on social media, so I implemented this rule with URL filtering (chat/messages/etc...) &lt;STRONG&gt;and&lt;/STRONG&gt; only allowing the appid "reddit-base", not "reddit-posting". This worked at the time, and has stopped functioning properly some time in the past year.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, users are still limited from messaging/chat/etc... but &lt;EM&gt;can&lt;/EM&gt; post comments and new threads on the site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This relates to SSL decryption as I was digging down the rabbit-hole and think that the "reddit-posting" appid has switched over to "web-browsing". I was wondering :&lt;/P&gt;
&lt;P&gt;1. If I implement SSL decryption on reddit, will it pick up the "reddit-posting" appid again?&lt;/P&gt;
&lt;P&gt;2. Why do I no longer see "reddit-posting" in my logs?&lt;/P&gt;
&lt;P&gt;3. What can SSL decryption do--or can't do--to help me solve this issue?&lt;/P&gt;
&lt;P&gt;4. Is this a more-so a question about how PA identifies appids for reddit?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you built the policy last year and it worked with the proper APP-ID being identified had SSL decryption been configured?&amp;nbsp; In general the answer is always going to be, yes, to ensure proper application of policy and identify traffic as the right APP-ID SSL decryption will always be looked at needing to be deployed.&amp;nbsp; SSL decryption breaks open the SSL/TLS packets exposing the encrypted payload.&amp;nbsp; APP-ID is going to be based on being able to properly see a packets contents/payload.&amp;nbsp; So if the packet is encrypted there's certainly going to be a limitation of Palo's ability to apply the correct application to traffic traversing the firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 21:39:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/382981#M89897</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2021-01-29T21:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption and Reddit Posting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/420117#M93848</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Did you add a ssl profile to the decryption rules as well? If so, check which ciphers you've selected as being ok, because this can be a cause of the Palo dropping the SSL connection.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Also if you are using Chrome, make sure you either disable the Quic protocol or block it on the Palo. Quic is Https over UDP, which the Palo can't decrypt. This only affects chrome though, so also check with IE to see if the same issues occur.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jul 2021 06:10:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/420117#M93848</guid>
      <dc:creator>brianpauler</dc:creator>
      <dc:date>2021-07-17T06:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption and Reddit Posting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/442221#M100079</link>
      <description>&lt;P&gt;As an update, we've implemented full SSL decryption since my original post for users, and now the issue persists by having&amp;nbsp;&lt;EM&gt;all&lt;/EM&gt; reddit related web traffic come through as "reddit-base". Previously--when first implemented--"reddit-posting" app-id would appear and function normally. By excluding this from our allow rule we could prevent users from messaging, signing in, commenting, etc... seems to not be the case anymore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a case with PA and they let me know this is a known issue being tracked as bug id&amp;nbsp;&lt;SPAN&gt;CON-50447 but I don't have much more information than that. They are able to reproduce on their end, so hopefully some additional visibility will help.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 14:21:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/442221#M100079</guid>
      <dc:creator>nreynders</dc:creator>
      <dc:date>2021-10-20T14:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption and Reddit Posting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/442222#M100080</link>
      <description>&lt;P&gt;Thanks for the additional info here! I have noticed Quic protocol coming through, but I can also replicate the issue on IE and Firefox.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We implemented SSL decryption for our users since the time of my first post, now all reddit related traffic comes through as "reddit-base", still no reddit-posting. PA verified that they can replicate the bug on their end, said they are looking into it with&amp;nbsp;&lt;SPAN&gt;CON-50447.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 14:25:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-reddit-posting/m-p/442222#M100080</guid>
      <dc:creator>nreynders</dc:creator>
      <dc:date>2021-10-20T14:25:08Z</dc:date>
    </item>
  </channel>
</rss>

