custom url filter action continue and ssl decryption

Reply
L4 Transporter

custom url filter action continue and ssl decryption

i have configured few custom url and action is set to continue.

for some https websites i get response page and when i click on continue it works fine.

 

for some https websites chrome shows error connection reset.

PCaps on PA does not show any drops.

traffic logs show session end reason threat and CLI shows discard.

 

below is custom url where action is continue which do not work

*.wcb.ab.ca/

wcb.ab.ca/

 

Above url works fine when ssl decryption is enabled.

Need to know response page with action as continue works for some https websites and not for others why?

 

 

MP
L7 Applicator

Re: custom url filter action continue and ssl decryption

Hello,

I suspect that this is getting blocked on a mismatched or not allowed Application. However since this is a medical site. I would suggest that you do not decrypt it, due to compliance and privacy issues. Here is a list of catagories we do not decrypt for this reason:

 

Military

Health and Medicine

Financial Services

Government

 

Regards,

L4 Transporter

Re: custom url filter action continue and ssl decryption

it is allowed application.

and we are not decrypting it.

MP
L7 Applicator

Re: custom url filter action continue and ssl decryption

What threat is it picking up on? Could be the website is compromised? 

L4 Transporter

Re: custom url filter action continue and ssl decryption

it shows threat due to url block

works fine when ssl is enabled.

 

 

MP
L7 Applicator

Re: custom url filter action continue and ssl decryption

Hello,

Check the Security policy to see which URL filter it is using then check the URL filter to see which catagories are blocked.

 

Regards,

L4 Transporter

Re: custom url filter action continue and ssl decryption

it is same rule and same url filtering profile.

MP
L7 Applicator

Re: custom url filter action continue and ssl decryption

Hmm, that is strange, maybe a tac case?

 

Custom catagories are processed prior to the Pre-Defined ones.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClH5CAK

 

 

L4 Transporter

Re: custom url filter action continue and ssl decryption

we open the tac case and issue was fixed via this

 

set deviceconfig setting ssl-decrypt url-proxy yes

 

As per Tac 

This enable the Palo Alto Networks device's ability to inject URL filtering response pages within an HTTPS session.

 

IF some here explain in more detail that will be much appreciated

MP
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!