<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Questions about the decryption performance of pa-5200 series in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/questions-about-the-decryption-performance-of-pa-5200-series/m-p/581558#M2880</link>
    <description>&lt;PRE class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Übersetzung" aria-label="Übersetzter Text" data-ved="2ahUKEwj4v9CG64-FAxXJZmwGHXcYAtoQ3ewLegQIExAU"&gt;&lt;SPAN class="Y2IQFc"&gt;The customer configures inbound decryption on the firewall. &lt;BR /&gt;When the decrypted traffic exceeds the processing performance of the firewall, &lt;BR /&gt;the firewall will not decrypt the traffic that needs to be decrypted. Will it be processed as normal traffic?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Übersetzung" aria-label="Übersetzter Text" data-ved="2ahUKEwj4v9CG64-FAxXJZmwGHXcYAtoQ3ewLegQIExAU"&gt;&lt;SPAN class="Y2IQFc"&gt;Can anyone explain this, thanks&lt;/SPAN&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 25 Mar 2024 16:34:30 GMT</pubDate>
    <dc:creator>Felixcao</dc:creator>
    <dc:date>2024-03-25T16:34:30Z</dc:date>
    <item>
      <title>Questions about the decryption performance of pa-5200 series</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/questions-about-the-decryption-performance-of-pa-5200-series/m-p/581558#M2880</link>
      <description>&lt;PRE class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Übersetzung" aria-label="Übersetzter Text" data-ved="2ahUKEwj4v9CG64-FAxXJZmwGHXcYAtoQ3ewLegQIExAU"&gt;&lt;SPAN class="Y2IQFc"&gt;The customer configures inbound decryption on the firewall. &lt;BR /&gt;When the decrypted traffic exceeds the processing performance of the firewall, &lt;BR /&gt;the firewall will not decrypt the traffic that needs to be decrypted. Will it be processed as normal traffic?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Übersetzung" aria-label="Übersetzter Text" data-ved="2ahUKEwj4v9CG64-FAxXJZmwGHXcYAtoQ3ewLegQIExAU"&gt;&lt;SPAN class="Y2IQFc"&gt;Can anyone explain this, thanks&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 25 Mar 2024 16:34:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/questions-about-the-decryption-performance-of-pa-5200-series/m-p/581558#M2880</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2024-03-25T16:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Questions about the decryption performance of pa-5200 series</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/questions-about-the-decryption-performance-of-pa-5200-series/m-p/581673#M2889</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76688"&gt;@Felixcao&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is documented under the decryption profile settings in the GUI. Alternatively, you can have a look at Techdoc&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-web-interface-help/objects/objects-decryption-profile/settings-to-control-decrypted-ssl-traffic" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-web-interface-help/objects/objects-decryption-profile/settings-to-control-decrypted-ssl-traffic&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have the option to terminate the sessions when resources are not available on the firewall. By default, this option is not checked.&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="table colsep rowsep  table-striped"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR class="row rowsep"&gt;
&lt;TD class="entry"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Block sessions if resources not available&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="entry relcol"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Terminate sessions if system resources are not available to process decryption.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Whether to block sessions when resources aren’t available is a tradeoff between tighter security and a better user experience. If you don’t block sessions when resources aren’t available, the firewall won’t be able to decrypt traffic that you want to decrypt when resources are impacted. However, blocking sessions when resources aren’t available may affect the user experience because sites that are normally reachable may become temporarily unreachable.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do not block the sessions when resources are not available, the traffic will go through encrypted provided that there is a security rule allowing it, but uninspected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--Richard&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 07:27:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/questions-about-the-decryption-performance-of-pa-5200-series/m-p/581673#M2889</guid>
      <dc:creator>rdumoulin</dc:creator>
      <dc:date>2024-03-26T07:27:47Z</dc:date>
    </item>
  </channel>
</rss>

