Issue with URL Category

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Issue with URL Category

L0 Member

We have just setup SSL decryption and added custom response pages on our firewall.  We have a custom filter for shopping sites and the category is set to alert, if a user is a member of an AD group associated with this filter it works fine.  We decided in our fall back filter to set the category to continue which would display a message and allow the user to click continue to the site.  The problem is any shopping site visited the user gets a generic page cannot be displayed in their browser, decryption is disabled for the shopping category but cannot determine why this is failing when other categories which are set to continue seem to work ok.  Any one have any ideas why this one category is not working correctly?

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Issue is that if traffic is HTTP then it goes like this.

 

SYN

SYN ACK

ACK

HTTP GET

Response containing website (Palo can intercept and send back continue page)

 

In case on HTTPS

SYN

SYN ACK

ACK

Client Hello

Server Hello

Server Certificate

HTTP GET (encrypted)

Response containing website (encrypted, Palo can't see this and cannot intercept)

 

 

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

Issue is that if traffic is HTTP then it goes like this.

 

SYN

SYN ACK

ACK

HTTP GET

Response containing website (Palo can intercept and send back continue page)

 

In case on HTTPS

SYN

SYN ACK

ACK

Client Hello

Server Hello

Server Certificate

HTTP GET (encrypted)

Response containing website (encrypted, Palo can't see this and cannot intercept)

 

 

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Yep of course seeing your explaination makes it clear, if the site is not decrypted then the firewall does not known what category the website is under and therefore does not display the response page, thanks.

It still knows because it can read domain and SNI information from the certificate but it can't see exact url visited.

For example Google services use *.google.com

So you don't know if user went to search, maps or some other service.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Great info Raido

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 2616 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!