cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

SSL Decryption - log for SSL certificate errors?

L2 Linker

Hi all,

 

We are using PANOS URL Filtering and SSL Decryption, and we reject a variety of SSL certificate problems such as expired certificates, SHA-1 signing, etc.  When one of our users hits one of these web sites, they get a "block" page.  This invariably leads them to submit a request to have the site unblocked, without any additional information. 

 

We have been unable to find any log on the Monitor tab of the firewall console that will give us the reason why the certificate was rejected.  At most we get traffic logs with "aged-out."  Is this information being collected by PANOS?  Is it available anywhere in the console?  How do other people diagnose these blocks?

 

Thanks,

- Steve

Who Me Too'd this topic