<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Forward Proxy Not Working in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/566469#M2127</link>
    <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt; Sorry for late reply. I have figured this out! Super easy and a tad embarrassing! The security rules were not setup properly so it simply was not been checked! Once I put the lan users in the lan zone, viola! it worked as expected. Thanks so much for your help I really appreciate it and those command are great too for future reference.&lt;/P&gt;
&lt;P&gt;Regards - Geoff&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2023 11:06:10 GMT</pubDate>
    <dc:creator>GWynn</dc:creator>
    <dc:date>2023-11-21T11:06:10Z</dc:date>
    <item>
      <title>SSL Forward Proxy Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565553#M2084</link>
      <description>&lt;P&gt;Hello all, another problem on my road to learning! I have created a self-signed CA Cert on my Palo Alto firewall. Exported to my Windows 10 box, imported into root CA store etc. I have set the cert as a Forward Trust Certificate, created a decryption policy and even added a custom SSL-Decrypt profile/policy. The action is decrypt. I can browse facebook.com but the cert is still signed by DigiCert Inc and not my firewall. Any thoughts? I have a security policy which allows all traffic to Web as I can get to FB etc. Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Geoff&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 11:10:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565553#M2084</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-11-14T11:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Forward Proxy Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565558#M2085</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Can you share your decryption rule? How it is configured?&lt;/P&gt;
&lt;P&gt;Have you checked if the page you are testing is not listed in Device -&amp;gt; SSL Decryption Exclusions &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-exclusions/palo-alto-networks-predefined-decryption-exclusions" target="_blank"&gt;Palo Alto Networks Predefined Decryption Exclusions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 13:14:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565558#M2085</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-11-14T13:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Forward Proxy Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565690#M2090</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GWynn_0-1699997145015.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55188i7BB11474EFDC3B6A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="GWynn_0-1699997145015.png" alt="GWynn_0-1699997145015.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GWynn_1-1699997161665.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55189i3EE4504F3B3B9C15/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="GWynn_1-1699997161665.png" alt="GWynn_1-1699997161665.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GWynn_2-1699997172589.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55190i9EA6DEDCA820F5E0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="GWynn_2-1699997172589.png" alt="GWynn_2-1699997172589.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GWynn_3-1699997185728.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55191i5E3CB80119AF5D44/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="GWynn_3-1699997185728.png" alt="GWynn_3-1699997185728.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GWynn_4-1699997203164.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55192iF4F48FA9870D27AB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="GWynn_4-1699997203164.png" alt="GWynn_4-1699997203164.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Morning &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt; Facebook is not on that list but very interesting, thank- you! I am also using generic sites such as &lt;A href="http://www.fast.com" target="_blank" rel="noopener"&gt;www.fast.com. &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.fast.com" target="_blank" rel="noopener"&gt;Here is my policy, thanks!&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 22:20:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565690#M2090</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-11-14T22:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Forward Proxy Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565808#M2095</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Is this virtual FW or physical?&lt;/P&gt;
&lt;P&gt;Is it lab FW without active licenses?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 11:28:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565808#M2095</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-11-15T11:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Forward Proxy Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565889#M2108</link>
      <description>&lt;P&gt;Hello, it is a virtual lab running on VMWorkstation I have active license for a week or so left!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 20:47:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565889#M2108</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-11-15T20:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Forward Proxy Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565890#M2109</link>
      <description>&lt;P&gt;Do you need a license for Forward Proxy etc? Looks like the answer is no, I researched then same back to this question!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 21:06:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565890#M2109</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-11-15T21:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Forward Proxy Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565955#M2112</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;In general SSL decryption does not require separate subcription license. Howerver I had experiance when working with old PA-3020, where support license had expired and any traffic sent to Content-ID process for inspection was dropped with reason "resource-unavailable".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your decryption rules find on first look, so it is hard to think your traffic is not matching it.&lt;/P&gt;
&lt;P&gt;Have you look at some of these commands - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF2CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClF2CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may also try to check the global counters for session that should be decrypted but it is not:&lt;/P&gt;
&lt;P&gt;1. Set a filter with source IP and destination port 443 - to capture any HTTPS traffic from your test machine&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2. Before opening the page run the show counter command with delta to reset the counters:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; show counter global filter packet-filter yes delta yes&lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;3. Open HTTPS page and reproduce the issue with page not being decrypted&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;4. Run show counters with delta gain and examine the output&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; show counter global filter packet-filter yes delta yes&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the output from the last show counters?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 09:31:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/565955#M2112</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-11-16T09:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Forward Proxy Not Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/566469#M2127</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt; Sorry for late reply. I have figured this out! Super easy and a tad embarrassing! The security rules were not setup properly so it simply was not been checked! Once I put the lan users in the lan zone, viola! it worked as expected. Thanks so much for your help I really appreciate it and those command are great too for future reference.&lt;/P&gt;
&lt;P&gt;Regards - Geoff&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 11:06:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ssl-forward-proxy-not-working/m-p/566469#M2127</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-11-21T11:06:10Z</dc:date>
    </item>
  </channel>
</rss>

