This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
I have seen some older posts with no updates on this very subject so I thought I would start a new thread. I am testing SSL decryption from a couple of workstations and have almost all of the traffic being successfully decrypted. We are a Google suite user with it being our email provider with our own domain. I am on a mac and when using Chrome to access any of the GSuite apps, it is not being decrypted. The cert is showing up as a standard Google Trust Services issued cert instead of my Palo Alto issued cert. I have blocked all QUIC traffic at the firewall per the Palo Alto published best practices. I have a security rule with any as the source, QUIC as the application and services as Application Default. Just to make sure something wasn't slipping past that rule I added another this morning blocking all udp traffic over 80 & 443 to no avail. The logs show tons of blocked QUIC traffic from my workstation. When I log into any of the GSuite apps from Safari, it is decrypted as expected. Any suggestions?
... View more