- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-06-2018 01:27 PM
I am currenlty doing a proof-of-concept test for the Credential Theft Protection feature. SSL decryption is configured and working. I can get the system to re-direct to the Anti Phishing Continue Page. However, that page uses the SSL cert associated with the Management SSL/TLS Service Profile. The browser will show the URL block page as https://98.136.144.138:6081/php/credentialblock.php?vsys=1<redacted>. Note that the IP seen here is for yahoo, not the IP of the firewall. As a result, we get an SSL error because the cert doesn't match the domain in the URL. If you add an exception for the site you will be able to view the Anti Phishing Continue page, but of course you would have to do this every time you got blocked. Is there a setting in the PAN that will have it use its own IP for the credentialblock.php page? Or is there a way to have this page served over http and not https?