AnyDesk Application is being decrypted and discarded, although it is in SSL decryption exclude list
2867
Created On 03/04/22 09:51 AM - Last Modified 07/12/25 02:26 AM
Symptom
- Adding "*.net.anydesktop.com" to the custom URL list and configuring the decryption policy with the action 'No Decrypt'.
- The traffic for "*.net.anydesktop.com" is decrypted and discarded with the Session End Reason "decrypt-cert-validation".
Environment
- Palo Alto Firewalls.
- Supported PAN-OS.
- SSL Decryption.
- AnyDesk Application.
Cause
The server certificate is untrusted by the firewall and so SSL exclusion is ignored.
Resolution
- Import the CA cert on the firewall and and mark it trusted
- Now the exclusion will work fine.