cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

When you visit SSL site then firewall sees certificate.

If you go to www.facebook.com then there is just Facebook and app is identified as facebook-base.

If you go to any Google service (maps.google.com, www.gmail.com etc) then cert says *.google.com and firewall is unable to identify exact application and uses broad google-base as application.

If there is no application for specific site then traffic is just identified as SSL.

 

If you have decryption policy in place then firewall can also detect subapplications like facebook-apps, facebook-chat etc

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

Who rated this post