<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do not decrypt bypass rule for domain in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4014808#M1010272</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* should be working fine. Infact they are using * in the snapshot I attached in previous comment.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jan 2020 18:13:52 GMT</pubDate>
    <dc:creator>Muhammad Awais Khan</dc:creator>
    <dc:date>2020-01-20T18:13:52Z</dc:date>
    <item>
      <title>Do not decrypt bypass rule for domain</title>
      <link>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4013513#M1010267</link>
      <description>&lt;P&gt;Is there a way to create a do not decrypt rule for a set of domains or FQDNs? I do not see a URL tab in the the SSL ACP. Running 6.4.0.4 fmc. Closest alternative is to either know the destination IPs or hope the application tab has a match.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 15:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4013513#M1010267</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-01-17T15:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Do not decrypt bypass rule for domain</title>
      <link>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4013874#M1010269</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I think there is no option to create rule with FQDN either you need to know the FQDN resolvable IP, If you try creating FQDN in the SLL rule it will not display FQDN objects there. I think its a limitation that cisco need to address in feature releases.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Abheesh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jan 2020 09:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4013874#M1010269</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2020-01-18T09:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Do not decrypt bypass rule for domain</title>
      <link>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4014382#M1010270</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you try with a rule using DN and CN ? you can match CN or DC for the required website which you dont want to decrypt.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 06:10:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4014382#M1010270</guid>
      <dc:creator>Muhammad Awais Khan</dc:creator>
      <dc:date>2020-01-20T06:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Do not decrypt bypass rule for domain</title>
      <link>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4014724#M1010271</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah so I tested adding a site to the subject DN and it didn't decrypt which is good. Does this also do subdomains or do you need to add an asterisk? I was under the impression firepower doesn't llike asterisk characters for wild card.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 15:40:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4014724#M1010271</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-01-20T15:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Do not decrypt bypass rule for domain</title>
      <link>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4014808#M1010272</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* should be working fine. Infact they are using * in the snapshot I attached in previous comment.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 18:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4014808#M1010272</guid>
      <dc:creator>Muhammad Awais Khan</dc:creator>
      <dc:date>2020-01-20T18:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Do not decrypt bypass rule for domain</title>
      <link>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4014872#M1010273</link>
      <description>&lt;P&gt;Thanks just tested the asterisk and it did work.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 20:30:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-not-decrypt-bypass-rule-for-domain/m-p/4014872#M1010273</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-01-20T20:30:16Z</dc:date>
    </item>
  </channel>
</rss>

