- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-15-2017 03:03 AM
We have such a problem with Microsoft Exchange OWA which we have recently published through Palo Alto.We have installed certificates with private keys,created necessary rules for PBF and NAT.
Everything is working fine except decryption.We can see in monitoring tab errors like decrypt-error or decrypt-unsupport-param
we have tried to connect from different browsers from outside with from TLS 1.0 to TLS 1.2
we also checked cypher suite which use our Exchange server and the clients' browser
also checked by packet capture
The interesting thing is that in some users there is no problem with decryption but in most users we see that problem
The version of Pan OS is 7.1.10
global protect version 4.0.4
the appliance is VM-300
12-15-2017 06:00 AM - edited 12-15-2017 06:03 AM
We had a similar Issue with Skype and Teams, what we did, we excluded from decrypt "internet-communications-and-telephony" category, for some reason that we don't know yet O365 apps does not like being decrypted, not a good solution but in the mean time could work for you.
12-18-2017 01:56 AM
ok i will try to check it
12-20-2017 11:40 AM
Any other suggestions
12-20-2017 01:37 PM
Hello,
There are definitly a lot of apps that dont like to be decrypted. A lot of the time its trial and error by watching the logs and testing real time. We had/have similar issues with Lync, basically we cant decrypt it and have to create bypass rules for ours as well as external parties that are hosting Lync/Skype conferences.
Good luck.
12-20-2017 01:56 PM
Here are a few links to hopefully help out.
https://live.paloaltonetworks.com/t5/Management-Articles/SSL-decryption-resource-list/ta-p/70397
Cheers!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!