<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Decryption firewall vs web proxy? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firewall-vs-web-proxy/m-p/41924#M30833</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the Palo Alto firewalls can do SSL decryption inbound and outbound in order to inspect the contents for threats is there an advantage to doing this on the palo firewall as opposed to the ironport web proxy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks to me like a good idea to do outbound SSL on the proxy as that would see the traffic first but inbound ssl to our servers on the firewall?&lt;/P&gt;&lt;P&gt;Thanks for any opinions,&lt;/P&gt;&lt;P&gt;Steve.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Mar 2014 18:35:32 GMT</pubDate>
    <dc:creator>sworton</dc:creator>
    <dc:date>2014-03-20T18:35:32Z</dc:date>
    <item>
      <title>SSL Decryption firewall vs web proxy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firewall-vs-web-proxy/m-p/41924#M30833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the Palo Alto firewalls can do SSL decryption inbound and outbound in order to inspect the contents for threats is there an advantage to doing this on the palo firewall as opposed to the ironport web proxy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks to me like a good idea to do outbound SSL on the proxy as that would see the traffic first but inbound ssl to our servers on the firewall?&lt;/P&gt;&lt;P&gt;Thanks for any opinions,&lt;/P&gt;&lt;P&gt;Steve.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Mar 2014 18:35:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firewall-vs-web-proxy/m-p/41924#M30833</guid>
      <dc:creator>sworton</dc:creator>
      <dc:date>2014-03-20T18:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption firewall vs web proxy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firewall-vs-web-proxy/m-p/41925#M30834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/26784"&gt;sworton&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The discussion here falls to 2 points &lt;/P&gt;&lt;P&gt;1&amp;gt; Where to do the proxy task&lt;/P&gt;&lt;P&gt;2&amp;gt; Which direction are we addressing ie client to server(c2s) or server to client (s2c)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we do the outbound traffic decryption on proxy and not on the firewall then all the traffic originating from inside network going to outside network is not decrypted to see underlying threat or identify the apps. So there is no visibility on the firewall.&lt;/P&gt;&lt;P&gt;If the traffic originates from outside then that holds good for the inbound decryption on the PAN which takes care as said above and you are fine for this direction.&lt;/P&gt;&lt;P&gt;So it all depends where the traffic originates from the firewall point that is inside network or outside and should we decrypt that traffic. If it is to be seen on both directions then both inbound and outbound decryption should be done.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Mar 2014 19:11:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-firewall-vs-web-proxy/m-p/41925#M30834</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2014-03-20T19:11:40Z</dc:date>
    </item>
  </channel>
</rss>

