ssl decryption and policy deny

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

ssl decryption and policy deny

Cyber Elite
Cyber Elite

 

I have configured ssl decryption and rule is there to allow the traffic 

IT is hitting the right rule but policy says denied?

 

 

what can be reason for this?

 

Capture.PNG

MP

Help the community: Like helpful comments and mark solutions.
2 accepted solutions

Accepted Solutions

Hello,

I was just thinking if you had a deny policy above the allow policy, doesnt look to be the case here. Check out the link that was posted, could be the issue.

 

Regards,

View solution in original post

5 REPLIES 5

Cyber Elite
Cyber Elite

Hello,

Would you also be able to post hte security policy rule that it is supposed to allow the traffic? I see its being decrypted but something is stopping it, maybe the policies are out of order? I see that the application is 'incomplete' this could be because of an out of order deny policy or routing.

 

Is the traffic allowed if decryption is disabled?

 

Just some thoughts,

@MP18

I am almost 100% certain that this is because of a decryption error

... https://live.paloaltonetworks.com/t5/General-Topics/Action-and-Session-End-Reason-conflict-when-SSL-...

yes i added the screenshot of security policy rule number 24

 

yes traffic is allowed

 

what is out of order policy?

Capture1.PNG

MP

Help the community: Like helpful comments and mark solutions.

Hello,

I was just thinking if you had a deny policy above the allow policy, doesnt look to be the case here. Check out the link that was posted, could be the issue.

 

Regards,

Many thanks Remo for replying to the post.

MP

Help the community: Like helpful comments and mark solutions.
  • 2 accepted solutions
  • 5650 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!