Actually we don't use ssl-decryption and we have problems with allowing SkyPe. We must allow SkyPe for some networks and block SkyPe for some networks. This did work fine before, with CheckPoint firewall and IronPort proxy, all was OK. CheckPoint blocked SkyPe totally, and SkyPe worked true proxy, using 443 port. But this doesn't work with PaloAlto, v5.0.2. I have checked the logs a lot, and seems that PaloAlto can detect Skype somehow 50/50. I also noticed, that destination IP -s, that PaloAlto detects as Skype, are sending ton's of packets back, but PaloAlto drops them all. This seems to be a bug. Some users can't connect. Some can. Some can connect, send messages, but can't make calls, messages are delayed etc. This is HUGE problem for us. I tried everything with PaloAlto, even allow only 443 port for Skype, still without luck. We tried upgrade SkyPe to the latest version, this is even worst for some users, seems PaloAlto can't detect SkyPe 6.1 properly. I asked to open support case also. What next?
... View more