We just switched to PAN DB and are using the PAN to do SSL decryption. The policy i am using also does not have safe search enforcement enabled.
What i have tried is, do a packet capture and found the exact uri, exempted that uri from decryption and allowed it on the policy. Added addition domains and urls found on google searches to the same exemption. Clip art contiunes to come back with the thumbnails exed out. We have users on Office 2013 and thier clip art thumbnails work fine, as it looks like that version just does a bing image search.
Anyone seen the issue and have possible work arounds that i did not try?
I'm not 100% clear on what you've set up but allow me to try and get you sorted
one important thing to consider when ssl is used, it that the URI in the http GET may differ significantly from the certificate's CN. Once ssl decryption is disabled, the http get will be invisible to the firewall so we can only base our actions on the CN or SNI.
if you filter out the IP of one of your hosts and try to load the clipart, can you differentiate which sessions are being blocked or which url lookups are denied (traffic log and url log). it may help in figuring out which url exactly is being blocked
If this isn't helpful, would you mind adding a few screenshots so we can see what you're seeing ?
In my PCAPs the URI isnt HTTPS its HTTP, I first i thought it was the SSL decrytption that was causing the issue so i wrote an exception. But looks like that isnt necessary, but for some reason its still broken. It works fine for the same user off of our network and not going through our PAN.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!