Network Security
Exclude a Server from Decryption for Technical Reasons (PAN-OS)
Table of Contents
Expand All
|
Collapse All
Network Security Docs
Exclude a Server from Decryption for Technical Reasons (PAN-OS)
- Log in to the web interface.Navigate to the SSL Decryption Exclusions list.Select DeviceCertificate ManagementSSL Decryption Exclusions.Add a new decryption exclusion, or select an existing custom entry to modify.
- Enter the hostname of the website or application you want to exclude from decryption. The hostname is case-sensitive.Make sure that the hostname field is unique for each custom entry. If a predefined exclusion matches a custom entry, the custom entry takes precedence.You can use wildcards to exclude multiple hostnames associated with a domain. The NGFW does not decrypt the sessions if the server presents a Common Name (CN) that matches the domain.(Optional) To share the exclusion across all virtual systems in a multiple virtual system NGFW, select Shared.Exclude the application from decryption.In contrast, you can deselect this option to begin decrypting an entry that was previously excluded from decryption.Click OK.Commit your changes.