Decryption Policy - Blocking things such as Facebook

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Decryption Policy - Blocking things such as Facebook

L1 Bithead

We recently discovered that due to Facebook now being https:// that my users can get out to Facebook when using Internet Explorer.  This actually cause quite an issue due to a bug also getting in.

How do I configure the decryption policy to get in to the session and block the traffic?  From what I'm reading I have to configure this to block https sites? 

Any assistance or advice would be greatly appreciated.

Thank you

1 accepted solution

Accepted Solutions

L7 Applicator

Hello kaysun,

1. PAN is having app-ID for facebook. Hence, you can block facebook through a deny rule, without having SSL decryption in place. we have multiple application-ID for facebook to have more granular control.

facebook-app.jpg

2. In general, for HTTPS (SSL) connection, PAN will not be able to verify the content of the packet. Hence, you may use the certificate name ( through URL filtering) to control that traffic.

Hope this helps.

Thanks

View solution in original post

2 REPLIES 2

L6 Presenter

Hi Kaysun,

Following document will help you to configure SSL decryption.

How to Implement SSL Decryption

Let me know for any query.

Regards,

Hardik Shah

L7 Applicator

Hello kaysun,

1. PAN is having app-ID for facebook. Hence, you can block facebook through a deny rule, without having SSL decryption in place. we have multiple application-ID for facebook to have more granular control.

facebook-app.jpg

2. In general, for HTTPS (SSL) connection, PAN will not be able to verify the content of the packet. Hence, you may use the certificate name ( through URL filtering) to control that traffic.

Hope this helps.

Thanks

  • 1 accepted solution
  • 1900 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!