User based ssl decryption

cancel
Showing results for 
Search instead for 
Did you mean: 

User based ssl decryption

L2 Linker

Hi,

 

I try to test ssl forward proxy decryption. It works fine if I use IP address as a source but if I use Users(domain) as a source it doesn't work. I can't use IP's for testing because our IP's floating. What I need to check in configuration?

 

Toni

1 ACCEPTED SOLUTION

Accepted Solutions

L4 Transporter

It seems the user to group mapping is not happening correctly. See this command for one ip

show user ip-user-mapping ip x.x.x.x

See if user is showing correctly

See also associated groups are showing correctly

If not add group mapping under Device-> user identification-> group mapping

PCNSE-7, ACE-6,ACE 7 , CCNP, CCNA,CCIE(theory) , RHCE
Firewalldog dot com

View solution in original post

12 REPLIES 12

L3 Networker

Is user identified properly and does show up on #show user ip-user-mapping all?

L7 Applicator

please take a look through this article to make sure UserID is set up properly:  Getting Started: User-ID

Tom Piens
PANgurus

Yep. User-ID works fine but user based decryption not.

That's odd.  We've been using TLS decryption for quite a while based on Active Directory group membership.  It works fine here (other than the fact that downloads over decrypted TLS sessions are incredibly slow).

Thanks for information. At least I know now that it could work.

Which version of PANOS are you running on?

I am running 7.0.5-h2, use user ID and do user based decryption as part of a pilot for decryption right now. No issues here.

Hello,

 

Our current version is 7.0.5-h2.

 

How you configure policy. Source address any and user domain\user ?

 

br

Toni

L4 Transporter

It seems the user to group mapping is not happening correctly. See this command for one ip

show user ip-user-mapping ip x.x.x.x

See if user is showing correctly

See also associated groups are showing correctly

If not add group mapping under Device-> user identification-> group mapping

PCNSE-7, ACE-6,ACE 7 , CCNP, CCNA,CCIE(theory) , RHCE
Firewalldog dot com

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!