<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Yes. It is generally in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssl-decrypting-only-search-engine-bound-traffic/m-p/2933914#M43555</link>
    <description>&lt;P&gt;Yes. It is generally recommended that an SSL decryption policy be restricted to the sites you really need to decrypt for just the reason you encountered.&lt;/P&gt;
&lt;P&gt;We would do this in your example by using an application rule in the SSL Policy.&lt;/P&gt;
&lt;P&gt;Config Guide Reference:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/Decryption_Tuning_Using_SSL_Rules.html#ID-2255-00000027&lt;/P&gt;
&lt;P&gt;Screenshot of example (open in new tab to zoom):&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ssl_decrypt_rule.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2016 20:21:30 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2016-09-26T20:21:30Z</dc:date>
    <item>
      <title>SSL Decrypting only search engine bound traffic</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decrypting-only-search-engine-bound-traffic/m-p/2933913#M43552</link>
      <description>&lt;P&gt;In the new release of FirePower 6.1 you can enable SafeSearch to restrict results of searches. &amp;nbsp;The only problem is that you have to use SSL,&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/firepower/610/relnotes/Firepower_System_Release_Notes_Version_610.html#pgfId-726143" target="_blank"&gt;6.1 release notes&lt;/A&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;It should be noted that SSL decryption policies must be configured for both of these features to work, especially because most search engines are now using SSL encryption.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;We recently had SSL decryption turned on and it was crashing the FirePower modules. &amp;nbsp;We were told by TAC that the 5545 with the modules couldn't handle the amount of SSL decryption we were doing. &amp;nbsp;So in the end we really didn't see a need to keep doing SSL decryption because of the performance lost. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"SafeSearch" is one feature as an education&amp;nbsp;institution&amp;nbsp;that we need to have turned on. &amp;nbsp;Is their a way to just send search engine bound traffic through SSL policy for decryption and "do not decrypt" all other traffic?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:41:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decrypting-only-search-engine-bound-traffic/m-p/2933913#M43552</guid>
      <dc:creator>tsiemers1</dc:creator>
      <dc:date>2019-03-10T13:41:26Z</dc:date>
    </item>
    <item>
      <title>Yes. It is generally</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decrypting-only-search-engine-bound-traffic/m-p/2933914#M43555</link>
      <description>&lt;P&gt;Yes. It is generally recommended that an SSL decryption policy be restricted to the sites you really need to decrypt for just the reason you encountered.&lt;/P&gt;
&lt;P&gt;We would do this in your example by using an application rule in the SSL Policy.&lt;/P&gt;
&lt;P&gt;Config Guide Reference:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/Decryption_Tuning_Using_SSL_Rules.html#ID-2255-00000027&lt;/P&gt;
&lt;P&gt;Screenshot of example (open in new tab to zoom):&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ssl_decrypt_rule.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 20:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decrypting-only-search-engine-bound-traffic/m-p/2933914#M43555</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-26T20:21:30Z</dc:date>
    </item>
  </channel>
</rss>

