Yesterday i upgraded my pa vm-100 from panos-7.01 to 7.02.
After that facebook stopped working with SSL decryption on.
After some testing and troubleshooting this seems to be the problem.
The problem is that some akamai domains that facebook uses gives me an palo alto certificate untrusted page.
for example this domain: https://fbcdn-profile-a.akamaihd.net
The strange thing is all the certificates used by this domain are already in de PA trusted cert auth list.
Just to be sure i downloaded the certs and added them manually to the PA, but no difference.
After spending 2 hours debugging en trying to get it work,
off course i can exclude those domains from decryption or or let the PA ingnore untrusted certs but thats not the way to do it. i downgraded to panos 7.0.1 and the untrusted cert problem dissapeared.
Are more people having this issue? i think there are more sites that stop working after the upgrade.
Does anyone found a solution?
Please let me know if this helps:
1) Instead of creating a separate cert to use as a forward untrust, try using the existing cert as both, forward trust and forward untrust.
2) Disable blocking of any untrusted issuers in the certificate profile or try disabling the cert profile altogether.
Having the same issues here as well. Funny thing is that I was seeing this for a few sites on 6.1.5 as well before moving to 7.0.2, but not nearly as often (like once a week someone would say Amazon wasn't working then it would "fix" itself randomly).
The interesting thing is that occasionlly i can get the eBay site to work in Chrome if i just keep hitting refresh, however I can never get it to work IE11.
Our decryption policy does not contain anything complicated (just trust to untrust) and does not utilize a decryption profile. I tried enabling the "default" decryption profile but that did not make any difference. I haven't tried creating a custom profile and playing around with any settings as of yet.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!