how can I know that traffic is hitting a configured decryption policy ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

how can I know that traffic is hitting a configured decryption policy ?

L0 Member

SSL decryption Policy question, how can I know that traffic is hitting a configured decryption policy ?

There's nothing in the Monitor Tab for decryption policies, nor can I get anything out of the CLI command "show log traffic rule equal DECRYPTION-RULE-NAME" ,

any ideas ?

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hello,

There are a lot of hidden Columns in the logs. To add them into the view, click one of the column headers and then hover your mouse over the Columns chevron and the display options appear.

OtakarKlier_0-1662490849280.png

 

The ones you will want to have checked are the following:

OtakarKlier_1-1662490919616.png

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decry...

 

Hope that helps.

View solution in original post

9 REPLIES 9

L6 Presenter

Do you have many decryption rules ?

if traffic hits a rule and is decrypted you can see it from monitor/traffic log inside magnifier

HI,

First match your decrytion policies, second, on a traffic log, you can click on small icon on the left and check if your session have been decrypteddecrypted.JPG

Rgds

L5 Sessionator

This cli command would help too

> show session all filter ssl-decrypt yes (under flag if you see an asterix that means the session is getting decrypted)

L0 Member

Thank you everyone for investing your time and effort in replying to my question Smiley Happy
And thank you sraghunandan for the tip on the cli command Smiley Wink

That is fine but how do you find which decryption policy it is hitting?

Cyber Elite
Cyber Elite

Hello,

There are a lot of hidden Columns in the logs. To add them into the view, click one of the column headers and then hover your mouse over the Columns chevron and the display options appear.

OtakarKlier_0-1662490849280.png

 

The ones you will want to have checked are the following:

OtakarKlier_1-1662490919616.png

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decry...

 

Hope that helps.

L6 Presenter

"Decryption Rule" must be a 10.x specific column as that does not show up in 9.x. However, you can test which decryption rule would apply to a given source/destination by using the 'Test Policy Match" tool at the bottom of the Decryption Policy page.

Hey, Adrian Thank you for the help.

Thank you, Otakar.

  • 1 accepted solution
  • 5878 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!