How to exclude IP address or Application from SSL Decrypt

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How to exclude IP address or Application from SSL Decrypt

L2 Linker

Hello everyone, 

 

How do you add an expecific application when there is no URLs inside the log?, I.E if you check the traffic logs it's showing SSL as Application and no more info rather than a destination IP that could be changing in the mayority of cases I see the "category" of the App but I don't want to exclude an entire caterory from SSL just a single App or IP Address, also in a different case I need to exclude an especific IP address from SSL decryption how do you achieve this ? thanks a lot in advance. 

1 accepted solution

Accepted Solutions

L2 Linker

You can't exclude "applications" from SSL Inspection as far as I know because the traffic has to be decrypted first so the PaloAlto's can identify the application.  As for whitelisting a domain or IP all you have to do is create a rule above the SSL inspection rule that specifies source and destination (with other stuff) and then select do not decrypt.  That should do the trick just fine unless the IPs are bouncing all over the place.  Then you would need to involve something like MineMeld.

View solution in original post

2 REPLIES 2

L2 Linker

You can't exclude "applications" from SSL Inspection as far as I know because the traffic has to be decrypted first so the PaloAlto's can identify the application.  As for whitelisting a domain or IP all you have to do is create a rule above the SSL inspection rule that specifies source and destination (with other stuff) and then select do not decrypt.  That should do the trick just fine unless the IPs are bouncing all over the place.  Then you would need to involve something like MineMeld.

@DIRTTI created a rule base on destination IP and it works perfectly, thanks.

  • 1 accepted solution
  • 5002 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!