<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Please tell me about Client to Firewall and Firewall to Client in the Strata Cloud Manager Firewall/Decryption log. in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/please-tell-me-about-client-to-firewall-and-firewall-to-client/m-p/1233020#M1177</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Attention: JAPAC TPM team&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Hello Team,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please tell me about Client to Firewall and Firewall to Client in the StrataCloudManager Firewall/Decryption log.&lt;/P&gt;
&lt;P&gt;My understanding of Client to Firewall and Firewall to Client is as follows.&lt;BR /&gt;-Client to Firewall: TLS handshake information sent by the client (Client Hello, etc.)&lt;BR /&gt;-Firewall to Client: TLS information responded by PrismaAccess (Server Hello, certificate, etc.)&lt;/P&gt;
&lt;P&gt;However, when I checked the log, the following was displayed.&lt;BR /&gt;-Client to Firewall: Server_Hello&lt;BR /&gt;-Firewall to Client: Client_Hello&lt;/P&gt;
&lt;P&gt;I think this is because PrismaAccess is acting as a proxy between the client and the server, but is this understanding correct?&lt;/P&gt;
&lt;P&gt;I would appreciate your advice.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jul 2025 09:08:09 GMT</pubDate>
    <dc:creator>y.saitou</dc:creator>
    <dc:date>2025-07-02T09:08:09Z</dc:date>
    <item>
      <title>Please tell me about Client to Firewall and Firewall to Client in the Strata Cloud Manager Firewall/Decryption log.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/please-tell-me-about-client-to-firewall-and-firewall-to-client/m-p/1233020#M1177</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Attention: JAPAC TPM team&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Hello Team,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please tell me about Client to Firewall and Firewall to Client in the StrataCloudManager Firewall/Decryption log.&lt;/P&gt;
&lt;P&gt;My understanding of Client to Firewall and Firewall to Client is as follows.&lt;BR /&gt;-Client to Firewall: TLS handshake information sent by the client (Client Hello, etc.)&lt;BR /&gt;-Firewall to Client: TLS information responded by PrismaAccess (Server Hello, certificate, etc.)&lt;/P&gt;
&lt;P&gt;However, when I checked the log, the following was displayed.&lt;BR /&gt;-Client to Firewall: Server_Hello&lt;BR /&gt;-Firewall to Client: Client_Hello&lt;/P&gt;
&lt;P&gt;I think this is because PrismaAccess is acting as a proxy between the client and the server, but is this understanding correct?&lt;/P&gt;
&lt;P&gt;I would appreciate your advice.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 09:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/please-tell-me-about-client-to-firewall-and-firewall-to-client/m-p/1233020#M1177</guid>
      <dc:creator>y.saitou</dc:creator>
      <dc:date>2025-07-02T09:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Please tell me about Client to Firewall and Firewall to Client in the Strata Cloud Manager Firewall/Decryption log.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/please-tell-me-about-client-to-firewall-and-firewall-to-client/m-p/1233369#M1182</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72491813"&gt;@y.saitou&lt;/a&gt;&amp;nbsp;, to answer your question,&amp;nbsp; In Strata Cloud Manager's Firewall/Decryption logs, the labels Client to Firewall and Firewall to Client refer to the direction of traffic as seen by the firewall, not necessarily the original source or destination of the TLS messages. When SSL Forward Proxy is enabled (which is common in Prisma Access deployments), the firewall intercepts and decrypts outbound SSL traffic by acting as a man-in-the-middle proxy. Here's how that affects the TLS handshake: (Check the attached table)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;So Why the Log Shows It Reversed&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Client to Firewall:&lt;/STRONG&gt; Server_Hello This is actually the Server Hello from the external server, received by the firewall after it initiated a second TLS handshake with the real destination.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Firewall to Client:&lt;/STRONG&gt; Client_Hello This is the Client Hello initiated by the firewall toward the external server, acting as a client.&lt;/P&gt;
&lt;P&gt;So yes, your understanding is correct. The firewall is proxying both sides of the handshake, and the logs reflect the firewall’s perspective of each leg of the TLS session.&lt;/P&gt;
&lt;P&gt;I hope you find this helpful.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jul 2025 15:10:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/please-tell-me-about-client-to-firewall-and-firewall-to-client/m-p/1233369#M1182</guid>
      <dc:creator>Vickynet</dc:creator>
      <dc:date>2025-07-05T15:10:53Z</dc:date>
    </item>
  </channel>
</rss>

