<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ssl-inbound inspection problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-problem/m-p/513905#M106707</link>
    <description>&lt;P&gt;Hello everyone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm configuring decryption with ssl-inbound inspection towards a nas synology via DNAT port-forwarding but i'm having trouble working with the following error that gives me the browser "PR_END_OF_FILE_ERROR". DNAT without ssl-inbound inspection works fine without certificate errors if I try to reach the web server from outside.&lt;/P&gt;
&lt;P&gt;I have imported the certificate and the priv-key of the synology correctly on the fw and applied to the decryption policy, but I doubt that the zone-level decryption policy is wrong.&lt;/P&gt;
&lt;P&gt;I post a couple of screens for completeness, decrypt, nat, security and logs&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="porq91_0-1662322178791.png" style="width: 1694px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43657i1102C0B490DEABD0/image-dimensions/1694x52/is-moderation-mode/true?v=v2" width="1694" height="52" role="button" title="porq91_0-1662322178791.png" alt="porq91_0-1662322178791.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="porq91_1-1662322223915.png" style="width: 1472px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43658i934A679A5845865A/image-dimensions/1472x81/is-moderation-mode/true?v=v2" width="1472" height="81" role="button" title="porq91_1-1662322223915.png" alt="porq91_1-1662322223915.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="porq91_2-1662322296995.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43659i9058C76067B4DAFB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="porq91_2-1662322296995.png" alt="porq91_2-1662322296995.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="porq91_0-1662322701882.png" style="width: 1008px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43661i405EE0D9DB236E4A/image-dimensions/1008x383/is-moderation-mode/true?v=v2" width="1008" height="383" role="button" title="porq91_0-1662322701882.png" alt="porq91_0-1662322701882.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actually topology:&amp;nbsp; internet---&amp;gt;router(dnat to ptp-fw)---&amp;gt;FW(dnat to synology TCP 5001)----&amp;gt;SYNOLOGY&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advice,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Angelo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 04 Sep 2022 20:19:17 GMT</pubDate>
    <dc:creator>porq91</dc:creator>
    <dc:date>2022-09-04T20:19:17Z</dc:date>
    <item>
      <title>ssl-inbound inspection problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-problem/m-p/513905#M106707</link>
      <description>&lt;P&gt;Hello everyone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm configuring decryption with ssl-inbound inspection towards a nas synology via DNAT port-forwarding but i'm having trouble working with the following error that gives me the browser "PR_END_OF_FILE_ERROR". DNAT without ssl-inbound inspection works fine without certificate errors if I try to reach the web server from outside.&lt;/P&gt;
&lt;P&gt;I have imported the certificate and the priv-key of the synology correctly on the fw and applied to the decryption policy, but I doubt that the zone-level decryption policy is wrong.&lt;/P&gt;
&lt;P&gt;I post a couple of screens for completeness, decrypt, nat, security and logs&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="porq91_0-1662322178791.png" style="width: 1694px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43657i1102C0B490DEABD0/image-dimensions/1694x52/is-moderation-mode/true?v=v2" width="1694" height="52" role="button" title="porq91_0-1662322178791.png" alt="porq91_0-1662322178791.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="porq91_1-1662322223915.png" style="width: 1472px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43658i934A679A5845865A/image-dimensions/1472x81/is-moderation-mode/true?v=v2" width="1472" height="81" role="button" title="porq91_1-1662322223915.png" alt="porq91_1-1662322223915.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="porq91_2-1662322296995.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43659i9058C76067B4DAFB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="porq91_2-1662322296995.png" alt="porq91_2-1662322296995.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="porq91_0-1662322701882.png" style="width: 1008px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43661i405EE0D9DB236E4A/image-dimensions/1008x383/is-moderation-mode/true?v=v2" width="1008" height="383" role="button" title="porq91_0-1662322701882.png" alt="porq91_0-1662322701882.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actually topology:&amp;nbsp; internet---&amp;gt;router(dnat to ptp-fw)---&amp;gt;FW(dnat to synology TCP 5001)----&amp;gt;SYNOLOGY&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advice,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Angelo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Sep 2022 20:19:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-problem/m-p/513905#M106707</guid>
      <dc:creator>porq91</dc:creator>
      <dc:date>2022-09-04T20:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: ssl-inbound inspection problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-problem/m-p/513950#M106715</link>
      <description>&lt;P&gt;There are other posts for such issues and you can google them but "PTP-FW-WAN2" is the destination address in your nat and security policies and for the security policy I think it should the translated internal zone address "SYNLOGY-NAC-...".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-policy-rules/nat-policy-overview" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-policy-rules/nat-policy-overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you still have issues see drop packet captures, global counters, flow basic etc:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-checking-for-drops-rejects-discards/td-p/402102" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-checking-for-drops-rejects-discards/td-p/402102&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still check that the app is indeed using normal SSL and that it is not using pinned SSL certs that can't be decrypted. You can look at the SSL logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloUCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloUCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2022 15:27:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-problem/m-p/513950#M106715</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-09-05T15:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: ssl-inbound inspection problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-problem/m-p/517875#M107448</link>
      <description>&lt;P&gt;If you managed to get the needed answers, please flag the question as answered.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 21:24:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection-problem/m-p/517875#M107448</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-10-13T21:24:23Z</dc:date>
    </item>
  </channel>
</rss>

