- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-15-2022 07:28 AM - edited 07-15-2022 07:37 AM
I would like to know how APP ID works when Palo alto firewall receives encrypted traffic but no ssl decryption is enabled.
07-15-2022 09:11 AM
The firewall still has limited insight into traffic even when you don't decrypt it. The accuracy of app-id goes down as we don't have full insight into the traffic, but that doesn't mean you can't identify some base IDs. Facebook and Google are prime examples of this; they'll show up as facebook-base and google-base even if you aren't decrypting the traffic, because you can still gather limited insight into where that traffic is going.
So in short, the firewall still has limited insight into encrypted traffic and will do its best to identify that traffic appropriately.
07-15-2022 09:11 AM
The firewall still has limited insight into traffic even when you don't decrypt it. The accuracy of app-id goes down as we don't have full insight into the traffic, but that doesn't mean you can't identify some base IDs. Facebook and Google are prime examples of this; they'll show up as facebook-base and google-base even if you aren't decrypting the traffic, because you can still gather limited insight into where that traffic is going.
So in short, the firewall still has limited insight into encrypted traffic and will do its best to identify that traffic appropriately.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!