Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Exclude www.google.* from decryption

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Exclude www.google.* from decryption

L4 Transporter

Hello,

are you able to exculde https://www.google.com ; https://www.google.de and other domains from SSL decryption?

Or clients complain about the slow loading of the website when they open Google or try to search something.

Currently i add in a white custom URL category:

www.google.com

www.google.com/

www.google.com/*

www.google.*

www.google.*/

www.google.*/*

and still the PA decrypt the traffic. If i try the policy from our location in US, it works (www.google.com). But if i try it from Germany - or other locations - the white list don't take affect.

Do you also have a slow loading of www.google.* if you enable ssl decyption?

17 REPLIES 17

L6 Presenter

If Im not mistaken you are supposed to use the stuff mentioned in the CN part of the cert being used at the server. Thats the only way PA can identify which site you are trying to reach when using HTTPS without actually decrypt anything.

Also it sounds strange that only google would be "slow".

Which hardware and panos do you use?

I know that PA-2000 series uses mgmtplane to generate the mitm-certs on the fly so in case mgmtplane is at 100% cpu then generating these mitm-certs would take an additional second(s) to complete and the client would experience this as a "slow" connection. However once terminated (since these certs I belienve are being cached) the speed should be good.

Other things to look into is how many bits the CA-cert is using (which will affect the time it takes to generate the mitm-cert on the fly).

Hi,

the thing is: www.google.(whatever) loads slow. Some second delay. Also when established once a connection (Google open in your browser and search again something).

And yes, we are using the "powerful" and "stable" PA2000 series......with 5.0.3.....In the last versions the problem was also available....

Checked the bits: With/Without Decryption - www.google.de - 1024         

Checked also hotmail.com: With Decryption: 1024 Without: 2048

(btw we using PA generated certificate for the ssl-decryption)

Whatever, i though to exclude the URL www.google.* as a workaround. But with my entries in the URL whitelist the PA still decrypt the session...?!

Not applicable

Possibly this document will help:

What I take away from it is that if you want to exclude a site from decryption, you need to create a custom URL category that lists that site by ip address (page 3) not by name.

I know its possible to exclude websites from decryption by adding the IP address....But i don't want to use IP address. Really need to exculde the URL www.google.* ...

I understand--I'm dealing with a similar issue myself. I'm working with support, and if I can get a config working I'll update this thread.

Thanks. Will be helpful!

Not applicable

You can exclude URLs by creating a Custom URL Category and add the sites into that URL Category then use the custom URL Category in your do not decrypt rule.

yes, i know...

thats my problem in this thread....its not possible.

L7 Applicator

Hi,

You could try to import cert used by google on the german site onto the PA device and then select the usage as "SSL Exclude Certificate" & see if you could prevent it from being decrypted.

capture2.PNG

Hi,

no it doesn't work. Whatever, our clients become accustomed to wait few seconds.

Hithead wrote:

And yes, we are using the "powerful" and "stable" PA2000 series......with 5.0.3.....In the last versions the problem was also available....

I hope you're being sarcastic here Smiley Happy The PA2000 series is neither powerful nor stable in my experience

egearhart wrote:

Hithead wrote:

And yes, we are using the "powerful" and "stable" PA2000 series......with 5.0.3.....In the last versions the problem was also available....

I hope you're being sarcastic here The PA2000 series is neither powerful nor stable in my experience

:smileylaugh: yes. Also had and have bad experience with the PA2000 series...

But however, the software should be able to exclude http://www.google.(de, com, nl, com.mx,... etc.) from the ssl decryption.

I was able to get this to work, but only with a custom category including:

*.google.*

*.google.*/*

google.*

google.*/*

so this would include mail.google.com, which I guess you don't want...

If I put in www.google.* some traffic remains undecrypted, but other is decrypted just like you said.

This means that making your own custom category to excluded from decryption does work, but just not always :-s

Do you have a support ticket open for this? If so, please keep us informed of the output.

Not applicable

Did you ever get his working for some reason ours that was working with a custom url category now is not working for wildcard urls in the category.

  • 7682 Views
  • 17 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!