<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL decription between firewall and proxy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decription-between-firewall-and-proxy/m-p/151120#M50086</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a palo alto 3020 firewall in peremeter and websense proxy server in internet network acting a explicit proxy. So users are browsing internet through proxy server and the proxy will forward the traffic to internet via PA firwall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need have following requirment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Enable ssl decrption in PA firewall and inspect any traffic coming from websense to inspect and if required to send suspicias trafic to wildfire cloud&lt;/P&gt;&lt;P&gt;* enable SSL decryption in websense and between clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so in two locations the traffic will be decrypted for insplection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the above scenario. Clients will have self signed certificate of websense. So websense will inspect traffic coming from clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So.. how to configure PA firewall for ssl decryption? is it similar to client to firewall decryption where we generate a self signed certificate and export it to websense. so firewall will act as MITM.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NEED your adivce on above setup?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Irshad&lt;/P&gt;</description>
    <pubDate>Tue, 04 Apr 2017 20:08:54 GMT</pubDate>
    <dc:creator>irshad.n</dc:creator>
    <dc:date>2017-04-04T20:08:54Z</dc:date>
    <item>
      <title>SSL decription between firewall and proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decription-between-firewall-and-proxy/m-p/151120#M50086</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a palo alto 3020 firewall in peremeter and websense proxy server in internet network acting a explicit proxy. So users are browsing internet through proxy server and the proxy will forward the traffic to internet via PA firwall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need have following requirment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Enable ssl decrption in PA firewall and inspect any traffic coming from websense to inspect and if required to send suspicias trafic to wildfire cloud&lt;/P&gt;&lt;P&gt;* enable SSL decryption in websense and between clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so in two locations the traffic will be decrypted for insplection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the above scenario. Clients will have self signed certificate of websense. So websense will inspect traffic coming from clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So.. how to configure PA firewall for ssl decryption? is it similar to client to firewall decryption where we generate a self signed certificate and export it to websense. so firewall will act as MITM.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NEED your adivce on above setup?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Irshad&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2017 20:08:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decription-between-firewall-and-proxy/m-p/151120#M50086</guid>
      <dc:creator>irshad.n</dc:creator>
      <dc:date>2017-04-04T20:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decription between firewall and proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decription-between-firewall-and-proxy/m-p/151148#M50091</link>
      <description>&lt;P&gt;essentially, yes. assuming you don't have an enterprise CA (which I'm guessing you don't, given that you're using a self-signed on the proxy).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what you may/should be able to do is export the private/public key of the cert on the proxy and import and use it as your forward trust certificate on the PA. that way you don't need to retrain any clients to trust the PA cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-and-Test-SSL-Decryption/ta-p/59719" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-and-Test-SSL-Decryption/ta-p/59719&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2017 22:10:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decription-between-firewall-and-proxy/m-p/151148#M50091</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-04T22:10:30Z</dc:date>
    </item>
  </channel>
</rss>

