Exclude www.google.* from decryption

Reply
Highlighted
L4 Transporter

Exclude www.google.* from decryption

Hello,

are you able to exculde https://www.google.com ; https://www.google.de and other domains from SSL decryption?

Or clients complain about the slow loading of the website when they open Google or try to search something.

Currently i add in a white custom URL category:

www.google.com

www.google.com/

www.google.com/*

www.google.*

www.google.*/

www.google.*/*

and still the PA decrypt the traffic. If i try the policy from our location in US, it works (www.google.com). But if i try it from Germany - or other locations - the white list don't take affect.

Do you also have a slow loading of www.google.* if you enable ssl decyption?

L6 Presenter

Re: Exclude www.google.* from decryption

If Im not mistaken you are supposed to use the stuff mentioned in the CN part of the cert being used at the server. Thats the only way PA can identify which site you are trying to reach when using HTTPS without actually decrypt anything.

Also it sounds strange that only google would be "slow".

Which hardware and panos do you use?

I know that PA-2000 series uses mgmtplane to generate the mitm-certs on the fly so in case mgmtplane is at 100% cpu then generating these mitm-certs would take an additional second(s) to complete and the client would experience this as a "slow" connection. However once terminated (since these certs I belienve are being cached) the speed should be good.

Other things to look into is how many bits the CA-cert is using (which will affect the time it takes to generate the mitm-cert on the fly).

L4 Transporter

Re: Exclude www.google.* from decryption

Hi,

the thing is: www.google.(whatever) loads slow. Some second delay. Also when established once a connection (Google open in your browser and search again something).

And yes, we are using the "powerful" and "stable" PA2000 series......with 5.0.3.....In the last versions the problem was also available....

Checked the bits: With/Without Decryption - www.google.de - 1024         

Checked also hotmail.com: With Decryption: 1024 Without: 2048

(btw we using PA generated certificate for the ssl-decryption)

Whatever, i though to exclude the URL www.google.* as a workaround. But with my entries in the URL whitelist the PA still decrypt the session...?!

Not applicable

Re: Exclude www.google.* from decryption

Possibly this document will help:

What I take away from it is that if you want to exclude a site from decryption, you need to create a custom URL category that lists that site by ip address (page 3) not by name.

L4 Transporter

Re: Exclude www.google.* from decryption

I know its possible to exclude websites from decryption by adding the IP address....But i don't want to use IP address. Really need to exculde the URL www.google.* ...

Not applicable

Re: Exclude www.google.* from decryption

I understand--I'm dealing with a similar issue myself. I'm working with support, and if I can get a config working I'll update this thread.

L4 Transporter

Re: Exclude www.google.* from decryption

Thanks. Will be helpful!

Not applicable

Re: Exclude www.google.* from decryption

You can exclude URLs by creating a Custom URL Category and add the sites into that URL Category then use the custom URL Category in your do not decrypt rule.

L4 Transporter

Re: Exclude www.google.* from decryption

yes, i know...

thats my problem in this thread....its not possible.

L7 Applicator

Re: Exclude www.google.* from decryption

Hi,

You could try to import cert used by google on the german site onto the PA device and then select the usage as "SSL Exclude Certificate" & see if you could prevent it from being decrypted.

capture2.PNG

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!