<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hi Claudiu , in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3385589#M1017218</link>
    <description>Not sure if this is still being followed or updated, but i'm having similar frustration.&lt;BR /&gt;What i did notice with sites like YOUTUBE, Google Docs, Google Drive.  In Firefox YOUTUBE will feed videos from a google site called 'c.docs.google.com' which is categorized as "Personal Storage". In IE it will come from a different site and categorized as "Streaming Media".  if your ACL is blocking category "Personal Storage" then that is why some users may work and others not.... check the browser and compare their session with the Event logs.  &lt;BR /&gt;When you say one user can access and another is blocked then verify the browser from both and see if Firefox/Chrome vs IE.  &lt;BR /&gt;two cents...</description>
    <pubDate>Fri, 18 May 2018 15:08:51 GMT</pubDate>
    <dc:creator>jdworak14</dc:creator>
    <dc:date>2018-05-18T15:08:51Z</dc:date>
    <item>
      <title>Firepower SSL decryption doesnt work well</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020742#M1017209</link>
      <description>&lt;P&gt;Hello ,I have configured FMC 6.2 with the Sensor 5525 ,configured SSL decryption ,when I access to https site i see my local certificate in my browser also can see it on logs that it was decrypted and resigned ! I want to allow facebook application but block facebook like or chat ,is that technically possible ? I cant find any documentation for that case !I will appreciate if anybody helps !&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:16:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020742#M1017209</guid>
      <dc:creator>hacizeynal</dc:creator>
      <dc:date>2019-03-12T13:16:32Z</dc:date>
    </item>
    <item>
      <title>You should be able to block</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020743#M1017210</link>
      <description>&lt;P&gt;You should be able to block these using an Access Control Policy.&lt;/P&gt;
&lt;P&gt;When you search for Applications as a condition, you will see the list that you need. Here is the screenshot showing the same:&lt;/P&gt;
&lt;P&gt;[[{"attributes":{},"fields":{}}]]&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 16:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020743#M1017210</guid>
      <dc:creator>syeda3</dc:creator>
      <dc:date>2017-02-03T16:18:21Z</dc:date>
    </item>
    <item>
      <title>(No subject)</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020744#M1017211</link>
      <description>&lt;P&gt;[[{"attributes":{},"fields":{}}]]&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 16:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020744#M1017211</guid>
      <dc:creator>syeda3</dc:creator>
      <dc:date>2017-02-03T16:31:10Z</dc:date>
    </item>
    <item>
      <title>It did not work for me ,I am</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020745#M1017212</link>
      <description>&lt;P&gt;It did not work for me ,I am still able to like posts on Facebook and etc, but In events I see that actually it is Blocked !&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 09:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020745#M1017212</guid>
      <dc:creator>hacizeynal</dc:creator>
      <dc:date>2017-02-06T09:57:34Z</dc:date>
    </item>
    <item>
      <title>Could you provide with some</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020746#M1017213</link>
      <description>&lt;P&gt;Could you provide with some screenshots of the events from the Table view of events?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 21:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020746#M1017213</guid>
      <dc:creator>Claudiu Cismaru</dc:creator>
      <dc:date>2017-02-16T21:13:53Z</dc:date>
    </item>
    <item>
      <title>Hi Claudiu ,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020747#M1017214</link>
      <description>&lt;P&gt;Hi Claudiu ,&lt;/P&gt;
&lt;P&gt;I have still issue on it ,although it shows in events that it is blocked it doesn't work ,i think it never works on Firepower or PaloAlto ,it is only possible to do it on Checkpoint &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; ,I am facing with another problem ,for example I have a department for Finance ,Youtube has been blocked ,one of user can access to it another one is not ? is it bug or something again ?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2017 11:20:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020747#M1017214</guid>
      <dc:creator>hacizeynal</dc:creator>
      <dc:date>2017-02-17T11:20:37Z</dc:date>
    </item>
    <item>
      <title>I am also have this issue. I</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020748#M1017215</link>
      <description>&lt;P&gt;I am also have this issue. I have configured a SSL decryption. When I go to Facebook I can see that the decrption is working but I am still allowed to comment and like.&lt;/P&gt;
&lt;P&gt;It looks like the micro application filtering does not work.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 08:59:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020748#M1017215</guid>
      <dc:creator>mlittleton</dc:creator>
      <dc:date>2017-04-07T08:59:24Z</dc:date>
    </item>
    <item>
      <title>Could you provide with some</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020749#M1017216</link>
      <description>&lt;P&gt;Could you provide with some screenshots of the events from the Table view of events for the ones you consider they should have been blocked?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 09:08:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020749#M1017216</guid>
      <dc:creator>Claudiu Cismaru</dc:creator>
      <dc:date>2017-04-07T09:08:01Z</dc:date>
    </item>
    <item>
      <title>I have attached the following</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020750#M1017217</link>
      <description>&lt;P&gt;I have attached the following screen shots SSL, Policy and events.&lt;/P&gt;
&lt;P&gt;In the policy I want to block &amp;nbsp;Facebook micro applications , Facebook messaging is blocked but all the rest of the application are not.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help will be appreciated. I am on &amp;nbsp;6.1.0.2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 10:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3020750#M1017217</guid>
      <dc:creator>mlittleton</dc:creator>
      <dc:date>2017-04-07T10:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Claudiu ,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3385589#M1017218</link>
      <description>Not sure if this is still being followed or updated, but i'm having similar frustration.&lt;BR /&gt;What i did notice with sites like YOUTUBE, Google Docs, Google Drive.  In Firefox YOUTUBE will feed videos from a google site called 'c.docs.google.com' which is categorized as "Personal Storage". In IE it will come from a different site and categorized as "Streaming Media".  if your ACL is blocking category "Personal Storage" then that is why some users may work and others not.... check the browser and compare their session with the Event logs.  &lt;BR /&gt;When you say one user can access and another is blocked then verify the browser from both and see if Firefox/Chrome vs IE.  &lt;BR /&gt;two cents...</description>
      <pubDate>Fri, 18 May 2018 15:08:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3385589#M1017218</guid>
      <dc:creator>jdworak14</dc:creator>
      <dc:date>2018-05-18T15:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: I have attached the following</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3385606#M1017219</link>
      <description>&lt;P&gt;It seems that not all the facebook traffic is being decrypted and if the traffic is encrypted the firepower can't tell which microapp it is.&amp;nbsp;If you specify an application that uses ssl in the decrypt policy it will never be decrypted.&lt;/P&gt;
&lt;P&gt;Also there a couple of bugs opened for firepower recognizing facebook microapplications, for instance:&amp;nbsp;CSCvh91548&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Bogdan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 15:34:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decryption-doesnt-work-well/m-p/3385606#M1017219</guid>
      <dc:creator>Bogdan Nita</dc:creator>
      <dc:date>2018-05-18T15:34:05Z</dc:date>
    </item>
  </channel>
</rss>

