<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Design suggestions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/design-suggestions/m-p/201391#M59529</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The decryption only happens within the PAN software and is not revealed. So in you scenario, it would look like the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;external client -&amp;gt; SSL-&amp;gt; PAN (decrypted and inspected) -&amp;gt; SSL -&amp;gt; Webserver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the only time its decrypted is so the PAN can inspect the traffic, i.e. within the device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense,&lt;/P&gt;</description>
    <pubDate>Tue, 20 Feb 2018 17:08:34 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-02-20T17:08:34Z</dc:date>
    <item>
      <title>Design suggestions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/design-suggestions/m-p/201211#M59492</link>
      <description>&lt;P&gt;We are trying to implement SSL offload using proxy gor our hosted websites, so they can be inspected by firewalls. Management currently is more alligned to SSL offload by proxy rather than decryption by FW and it is working the way below. But with the cenario below they are also concerned about the password being revealed after SSL offload. How can i mitigate that. This is a typical web application scenario for us and is using web servers uing ldap/s.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 696px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13854iEE67E26304E55551/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 21:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/design-suggestions/m-p/201211#M59492</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2018-02-19T21:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Design suggestions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/design-suggestions/m-p/201391#M59529</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The decryption only happens within the PAN software and is not revealed. So in you scenario, it would look like the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;external client -&amp;gt; SSL-&amp;gt; PAN (decrypted and inspected) -&amp;gt; SSL -&amp;gt; Webserver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the only time its decrypted is so the PAN can inspect the traffic, i.e. within the device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense,&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 17:08:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/design-suggestions/m-p/201391#M59529</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-20T17:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Design suggestions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/design-suggestions/m-p/201410#M59535</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;Management is more alligned to SSL offload by the proxy rather than decryption by firewall. Once traffic enters firewall it is encrypted, it then exits to reach proxy where it is&amp;nbsp;decrypted and then enters back into firewall and then out to the server.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 17:28:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/design-suggestions/m-p/201410#M59535</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2018-02-20T17:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Design suggestions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/design-suggestions/m-p/201413#M59537</link>
      <description>&lt;P&gt;Maybe have a small subnet between the proxy and the server? That way its locked into that small area, like a DMZ.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 17:41:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/design-suggestions/m-p/201413#M59537</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-20T17:41:35Z</dc:date>
    </item>
  </channel>
</rss>

