Domains
There are a number of Domains/SSL Certificates that are excluded from SSL Decryption.
Starting with PAN-OS 8.0 and newer, the SSL exclusion is handled inside of the Certificates section of the WebUI.
To see the full list of domains/SSL certificates that are excluded from SSL Dectyption, Inside of the WebGUI > Device > Certificate Management > SSL Decryption Exclusion.
The domains selected with the "Exclude from decryption" in this location will not be decrypted by the Palo Alto Networks device.
This list of domains are added the SSL Decryption Exclusion list in each Content load so that the SSL engine will allow them to pass through, rather than trying to decrypt them.
Applications
In PAN-OS 7.1 and older, applications were used instead of domains.
These applications are added to an exclude list in each Content load so that the SSL engine will allow them to pass through, rather than trying to decrypt them.
#
|
Application
|
---|
1 | adobe-echosign |
2 | aerofs |
3 | aim |
4 | airdroid |
5 | amazon-aws-console |
6 | anydesk |
7 | appguru |
8 | apple-game-center |
9 | apple-push-notifications |
10 | asana |
11 | authentic8-silo |
12 | bluejeans |
13 | cryptocat |
14 | daum-mypeople |
15 | discord |
16 | dnf |
17 | efolder |
18 | evault |
19 | filesanywhere |
20 | finch |
21 | google-plus-posting |
22 | gotoassist |
23 | gotomeeting |
24 | gotomypc |
25 | hbo |
26 | hp-virtual-rooms |
27 | icloud |
28 | informatica-cloud |
29 | itunes |
30 | itunes-appstore |
31 | itunes-mediastore |
32 | itwin |
33 | jungledisk |
34 | kakaotalk |
35 | kakaotalk-audio-chat |
36 | kakaotalk-file-transfer |
37 | lantern |
38 | linkedin |
39 | live-mesh |
40 | logentries |
41 | logmein |
42 | logmeinrescue |
43 | meerkat |
44 | megachat |
45 | metatrader |
46 | minecraft |
47 | ms-lync-online |
48 | ms-product-activation |
49 | ms-spynet |
50 | ms-update |
51 | naver-line |
52 | norton-zone |
53 | ntr-support |
54 | odrive |
55 | office-on-demand |
56 | okta |
57 | onepagecrm |
58 | onlive |
59 | opera-vpn |
60 | packetix-vpn |
61 | paloalto-wildfire-cloud |
62 | pando |
63 | pathview |
64 | periscope |
65 | proofhq |
66 | puffin |
67 | rift |
68 | second-life |
69 | signal |
70 | silent-circle |
71 | simplify |
72 | sophos-rms |
73 | springcm |
74 | sugarsync |
75 | telex |
76 | tigertext |
77 | ubuntu-one |
78 | ultrasurf |
79 | vagrant |
80 | via3 |
81 | vmware-view |
82 | vudu |
83 | wallcooler-vpn |
84 | webroot-secureanywhere |
85 | wetransfer |
86 | whatsapp |
87 | winamax |
88 | wiredrive |
89 | yunpan360-file-transfer |
90 | yuuguu |
91 | zoom |
92 | zumodrive |