09-02-2020 12:49 PM
I have a "continue" policy set on newly registered domains category. If I visit a site with https I see the continue page but upon clicking continue the block page just refreshes (the guid in the address bar changes).
If I visit the site without SSL, the block page appears, and clicking continue will correctly take me to the site.
What have I misconfigured? I do not have SSL Decryption set up in general and did follow the KB article "How to Serve a URL Response Page Over an HTTPS Session Without SSL Decryption" and I am not getting any sort of cert error.
12-02-2020 05:37 PM
The idea of creating certificates locally in order to server up a response page without decryption, is a hit and miss, based on how the individual website is seen/received by the PANW FW.
My question is surrounding why you would not start to implement decryption for Internet based traffic.
Is there a question/concern that prevents you from want to implement it.
About 80% of websites are SSL encrypted, that means AV, spyware, and vulnerabilities, ransomeware can enter your network, because you are not decrypting.
Your users can/probably are exfiltrating data out of the network, providing loss of intellectual property, credit card, PII, etc.
It is recommended that ALL companies start to deploy certs and roll them out to their users.
You have already done a large amount of work already... just need to get the certs from the FW (or the root CA) deployed to your users.
Is there hesitations, and how can we in Live, assist you and your company through making these very important modifications to your configuration?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!