How to exclude IP address or Application from SSL Decrypt

Reply
L2 Linker

How to exclude IP address or Application from SSL Decrypt

Hello everyone, 

 

How do you add an expecific application when there is no URLs inside the log?, I.E if you check the traffic logs it's showing SSL as Application and no more info rather than a destination IP that could be changing in the mayority of cases I see the "category" of the App but I don't want to exclude an entire caterory from SSL just a single App or IP Address, also in a different case I need to exclude an especific IP address from SSL decryption how do you achieve this ? thanks a lot in advance. 

L2 Linker

Re: How to exclude IP address or Application from SSL Decrypt

You can't exclude "applications" from SSL Inspection as far as I know because the traffic has to be decrypted first so the PaloAlto's can identify the application.  As for whitelisting a domain or IP all you have to do is create a rule above the SSL inspection rule that specifies source and destination (with other stuff) and then select do not decrypt.  That should do the trick just fine unless the IPs are bouncing all over the place.  Then you would need to involve something like MineMeld.

Highlighted
L2 Linker

Re: How to exclude IP address or Application from SSL Decrypt

@DIRTTI created a rule base on destination IP and it works perfectly, thanks.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!