<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall cert-SSL forward proxy-To actual destination, in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223801#M64331</link>
    <description>&lt;P&gt;I know for a fact that firewall intercepts SSL connection&amp;nbsp; and generates on-the-fly cert to clients under decryption scenario. But, I wasn't able to find enough resources explaning how firewall intitates connection to the actual destination on client behalf? I mean to ask does the firewall uses palo default cert as personal certificate when intitating this connection?if so,where can I find it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me understand this. TIA&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jul 2018 15:29:46 GMT</pubDate>
    <dc:creator>SThatipelly</dc:creator>
    <dc:date>2018-07-27T15:29:46Z</dc:date>
    <item>
      <title>Firewall cert-SSL forward proxy-To actual destination,</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223801#M64331</link>
      <description>&lt;P&gt;I know for a fact that firewall intercepts SSL connection&amp;nbsp; and generates on-the-fly cert to clients under decryption scenario. But, I wasn't able to find enough resources explaning how firewall intitates connection to the actual destination on client behalf? I mean to ask does the firewall uses palo default cert as personal certificate when intitating this connection?if so,where can I find it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me understand this. TIA&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 15:29:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223801#M64331</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2018-07-27T15:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall cert-SSL forward proxy-To actual destination,</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223828#M64334</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What the firewall actually does here is a &lt;A href="https://en.m.wikipedia.org/wiki/Man-in-the-middle_attack" target="_blank"&gt;Man-in-the-middle attack&lt;/A&gt; on TLS connections. As you already wrote it terminates the connection and presents an on the fly generated cert to the client. This is the first connection (between client and the firewall). The second one is the connection that the firewall initiates towards the server. For this connection, the firewall does initiate a connection to the server without any client certificate - simply because there is no client cert required.&lt;/P&gt;&lt;P&gt;If your question is about connections where a client cert is required: these connections the firewall cannot decrypt. So for these you have to configure exceptions to make them work.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 18:17:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223828#M64334</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-27T18:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall cert-SSL forward proxy-To actual destination,</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223835#M64335</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;Thank you for the response.&amp;nbsp;I'll try to reword my question :When firewall performs a connection to server,what certificate does it use to identify itself to server? where can I find it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 18:22:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223835#M64335</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2018-07-27T18:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall cert-SSL forward proxy-To actual destination,</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223838#M64336</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It doesn't use a certificate to identify itself to the server; you can't decrypt anything that actually requires a client cert.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 18:55:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223838#M64336</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-27T18:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall cert-SSL forward proxy-To actual destination,</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223840#M64338</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;&lt;/P&gt;&lt;P&gt;As I wrote there is no certificate that the firewall uses to identify itself. In a standard TLS handshake only the server identifies itsself to the client - not otherwise. And this is what the firewall does in this case where the firewall has the role of the client. (&lt;A href="https://en.m.wikipedia.org/wiki/Transport_Layer_Security" target="_blank"&gt;https://en.m.wikipedia.org/wiki/Transport_Layer_Security&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 18:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-cert-ssl-forward-proxy-to-actual-destination/m-p/223840#M64338</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-27T18:58:43Z</dc:date>
    </item>
  </channel>
</rss>

