<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption and Forward decrypted content to WildFire Query in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-forward-decrypted-content-to-wildfire-query/m-p/456295#M101697</link>
    <description>&lt;P&gt;Dear BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your update and really Appreciate .&lt;/P&gt;&lt;P&gt;I Agreed for your second point related to Wildfire Encryption will be no effect.&lt;/P&gt;&lt;P&gt;For 1st step&lt;BR /&gt;Traffic flow as below&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Internal Domain Users--PA FW---DMZ Proxy---PA FW--Internet.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;so we installed only Proxy Certificate to the users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW Policy:&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;1st rule&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;src:internal user dst:proxy with service port&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;2nd rule&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;src:proxy dst:internet with service port&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Do we really need to enable ssl decryption in this case or not.if yes how can i enable decryption rule&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;src:inside&amp;nbsp; dst:outside or&amp;nbsp; &amp;nbsp; src:inside&amp;nbsp; &amp;nbsp;dst:dmz&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;will it make any performance issue or traffic delay. Please confirm.&lt;/P&gt;</description>
    <pubDate>Sat, 01 Jan 2022 05:48:54 GMT</pubDate>
    <dc:creator>YazarArafath</dc:creator>
    <dc:date>2022-01-01T05:48:54Z</dc:date>
    <item>
      <title>SSL Decryption and Forward decrypted content to WildFire Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-forward-decrypted-content-to-wildfire-query/m-p/455867#M101675</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have below 2 tasks which needs to be closed from PaloAlto Level. Appreciate your quick response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#333333"&gt;&lt;STRONG&gt;&lt;U&gt;Task 1&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#0000FF"&gt;"1.Configure SSL Forward Proxy for all traffic destined to the Internet"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;As per the Best Practices we have to enable ssl Decryption for Internet Traffic for that we have to push Certificate to Domain users but My case we have separate Proxy for http and HTTPs Traffic which is in DMZ Zone so we pushed only Proxy certificate to Clients.&lt;/P&gt;
&lt;P&gt;In that case Traffic going via Proxy.&lt;/P&gt;
&lt;P&gt;Kindly share the PA Recommendation whether i have to enable again for all clients with PA CA certificate or not.&lt;/P&gt;
&lt;P&gt;Kindly confirm how to fix this Task 1.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#333333"&gt;&lt;U&gt;Task 2&lt;/U&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#0000FF"&gt;"Allow the firewall to forward decrypted content to WildFire. Note that SSL Forward-Proxy must also be enabled and configured for this setting to take effect on inside-to-outside traffic flows"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what will happen if i enable this option since i didn't enabled SSL decryption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly confirm how to fix this Task 2.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 17:41:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-forward-decrypted-content-to-wildfire-query/m-p/455867#M101675</guid>
      <dc:creator>YazarArafath</dc:creator>
      <dc:date>2021-12-29T17:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption and Forward decrypted content to WildFire Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-forward-decrypted-content-to-wildfire-query/m-p/456081#M101676</link>
      <description>&lt;P&gt;Anyone please respond will be helpful&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 16:37:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-forward-decrypted-content-to-wildfire-query/m-p/456081#M101676</guid>
      <dc:creator>YazarArafath</dc:creator>
      <dc:date>2021-12-30T16:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption and Forward decrypted content to WildFire Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-forward-decrypted-content-to-wildfire-query/m-p/456124#M101681</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/143673"&gt;@YazarArafath&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. If you're decrypting traffic you'll need to deploy the Forward Trust certificate to the endpoints so that it's actually trusted, or have your root and intermediate certificates trusted by the clients if using an internal PKI. Depending on how you're proxying traffic you wouldn't necessarily need to deploy it to the client and would only need it on the proxy, but that's dependent on how you have things configured.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Nothing. The setting simply enables the firewall to to send decrypted traffic to Wildfire for analysis. If you aren't inspecting traffic what you are enabling has zero effect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 20:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-forward-decrypted-content-to-wildfire-query/m-p/456124#M101681</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-12-30T20:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption and Forward decrypted content to WildFire Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-forward-decrypted-content-to-wildfire-query/m-p/456295#M101697</link>
      <description>&lt;P&gt;Dear BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your update and really Appreciate .&lt;/P&gt;&lt;P&gt;I Agreed for your second point related to Wildfire Encryption will be no effect.&lt;/P&gt;&lt;P&gt;For 1st step&lt;BR /&gt;Traffic flow as below&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Internal Domain Users--PA FW---DMZ Proxy---PA FW--Internet.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;so we installed only Proxy Certificate to the users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW Policy:&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;1st rule&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;src:internal user dst:proxy with service port&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;2nd rule&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;src:proxy dst:internet with service port&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Do we really need to enable ssl decryption in this case or not.if yes how can i enable decryption rule&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;src:inside&amp;nbsp; dst:outside or&amp;nbsp; &amp;nbsp; src:inside&amp;nbsp; &amp;nbsp;dst:dmz&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;will it make any performance issue or traffic delay. Please confirm.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jan 2022 05:48:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-and-forward-decrypted-content-to-wildfire-query/m-p/456295#M101697</guid>
      <dc:creator>YazarArafath</dc:creator>
      <dc:date>2022-01-01T05:48:54Z</dc:date>
    </item>
  </channel>
</rss>

