Hi @Charlie80 ,
@Adrian_Jensen makes a good point. Best practices for outbound SSL decryption includes a no decrypt rule for certain categories such as "financial-services, health-and-medicine, government, and any other categories you don’t want to decrypt for business, legal, or regulatory reasons" https://docs.paloaltonetworks.com/best-practices/9-1/decryption-best-practices/decryption-best-practices/deploy-ssl-decryption-using-best-practices
It also says you can add sites to the built-in SSL Decryption Exclusion list. If you click on the Decryption Best Practices link at the top, you will also see guidance on planning your configuration. A critical piece is to "Work with and educate stakeholders such as legal, finance, HR, executives, security, and IT/support to develop a decryption deployment strategy."
Thanks,
Tom
... View more