- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-08-2015 01:34 PM
Hi all,
We are using PANOS URL Filtering and SSL Decryption, and we reject a variety of SSL certificate problems such as expired certificates, SHA-1 signing, etc. When one of our users hits one of these web sites, they get a "block" page. This invariably leads them to submit a request to have the site unblocked, without any additional information.
We have been unable to find any log on the Monitor tab of the firewall console that will give us the reason why the certificate was rejected. At most we get traffic logs with "aged-out." Is this information being collected by PANOS? Is it available anywhere in the console? How do other people diagnose these blocks?
Thanks,
- Steve