Issue with URL Category

Reply
Highlighted
L0 Member

Issue with URL Category

We have just setup SSL decryption and added custom response pages on our firewall.  We have a custom filter for shopping sites and the category is set to alert, if a user is a member of an AD group associated with this filter it works fine.  We decided in our fall back filter to set the category to continue which would display a message and allow the user to click continue to the site.  The problem is any shopping site visited the user gets a generic page cannot be displayed in their browser, decryption is disabled for the shopping category but cannot determine why this is failing when other categories which are set to continue seem to work ok.  Any one have any ideas why this one category is not working correctly?


Accepted Solutions
Highlighted
L7 Applicator

Issue is that if traffic is HTTP then it goes like this.

 

SYN

SYN ACK

ACK

HTTP GET

Response containing website (Palo can intercept and send back continue page)

 

In case on HTTPS

SYN

SYN ACK

ACK

Client Hello

Server Hello

Server Certificate

HTTP GET (encrypted)

Response containing website (encrypted, Palo can't see this and cannot intercept)

 

 

 

Enterprise Architect @ Cloud Carib www.cloudcarib.com
ACE, PCNSE, PCNSI

View solution in original post


All Replies
Highlighted
L7 Applicator

Issue is that if traffic is HTTP then it goes like this.

 

SYN

SYN ACK

ACK

HTTP GET

Response containing website (Palo can intercept and send back continue page)

 

In case on HTTPS

SYN

SYN ACK

ACK

Client Hello

Server Hello

Server Certificate

HTTP GET (encrypted)

Response containing website (encrypted, Palo can't see this and cannot intercept)

 

 

 

Enterprise Architect @ Cloud Carib www.cloudcarib.com
ACE, PCNSE, PCNSI

View solution in original post

Highlighted
L0 Member

Yep of course seeing your explaination makes it clear, if the site is not decrypted then the firewall does not known what category the website is under and therefore does not display the response page, thanks.

Highlighted
L7 Applicator

It still knows because it can read domain and SNI information from the certificate but it can't see exact url visited.

For example Google services use *.google.com

So you don't know if user went to search, maps or some other service.

Enterprise Architect @ Cloud Carib www.cloudcarib.com
ACE, PCNSE, PCNSI
Highlighted
Cyber Elite

Great info Raido

MP
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!