Online payment with SSL decryption

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Online payment with SSL decryption

L1 Bithead

Hi

We have SSL decryption enabled on our PA NGFWs but our users have reported issues relating to online payment transactions. We have worked around this by creating a whitelist to bypass decryption but as more sites offer payment facilities online, it will eventually become unfeasible to maintain a bypass list. What is Palo's approach to dealing with this? Are other organizations facing the same issue and how are they dealing with it? 

3 REPLIES 3

Cyber Elite
Cyber Elite

Thank you for your post @Joe_Ng 

 

Palo Alto's recommendation is to exclude whole URL category: "financial-services" https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-exclusions/create-a-... This should cover sites that you get redirected to for online payments.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi

 

Thank you for your response. The URL category 'financial services' has already been included in a non-decrypt policy before the decrypt all policy. I suspect some sites may be running these services behind URLs that may be not be categorized under financial services. 

Cyber Elite
Cyber Elite

Thank you for reply @Joe_Ng 

 

I see. If you believe there is a URL mis-categorization, you can submit a request from this link: https://urlfiltering.paloaltonetworks.com/

Other than what you are already doing with a manual whitelist, I can't think of any better way to avoid the issue you reported.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 2265 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!