<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: show system setting ssl-decrypt certificate -----No inbound cert in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/show-system-setting-ssl-decrypt-certificate-no-inbound-cert/m-p/237660#M68093</link>
    <description>&lt;P&gt;There are two types of SSL decryption policies - inbound decryption and Forward Proxy decryption.&amp;nbsp; It sounds like you have a policy that matched on an inbound decryption policy.&amp;nbsp; This is useful if you are hosting a server (e.g. in a DMZ) and have both the public and private certificates for that SSL/TLS server loaded onto the firewall, and you wish to do an inbound decryption inspection of the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have users trying to visit a website on the internet, you want a forward proxy decryption policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Oct 2018 17:49:09 GMT</pubDate>
    <dc:creator>JW6224</dc:creator>
    <dc:date>2018-10-29T17:49:09Z</dc:date>
    <item>
      <title>show system setting ssl-decrypt certificate -----No inbound cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-system-setting-ssl-decrypt-certificate-no-inbound-cert/m-p/237651#M68091</link>
      <description>&lt;P&gt;show system setting ssl-decrypt certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certificates for Global&lt;/P&gt;&lt;P&gt;SSL Decryption CERT&lt;/P&gt;&lt;P&gt;global trusted&lt;BR /&gt;ssl-decryption x509 certificate&lt;BR /&gt;version 2&lt;BR /&gt;cert algorithm 4&lt;BR /&gt;valid 171204224608Z -- 221204225608Z&lt;BR /&gt;cert pki 1&lt;BR /&gt;subject: NGFW-2&lt;BR /&gt;issuer: Root CA 2&lt;BR /&gt;serial number(19)&lt;BR /&gt;4f 00 00 00 2b e2 bd d9 f7 cb fa 0b 9a 00 01 00 O...+... ........&lt;BR /&gt;00 00 2b ..+&lt;BR /&gt;rsa key size 2048 bits siglen 512 bytes&lt;BR /&gt;basic constraints extension CA 1&lt;BR /&gt;also serves as untrusted certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;NO INBOUND CERT&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to know what does no&amp;nbsp; inbound cert mean here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 17:43:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-system-setting-ssl-decrypt-certificate-no-inbound-cert/m-p/237651#M68091</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-29T17:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: show system setting ssl-decrypt certificate -----No inbound cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-system-setting-ssl-decrypt-certificate-no-inbound-cert/m-p/237660#M68093</link>
      <description>&lt;P&gt;There are two types of SSL decryption policies - inbound decryption and Forward Proxy decryption.&amp;nbsp; It sounds like you have a policy that matched on an inbound decryption policy.&amp;nbsp; This is useful if you are hosting a server (e.g. in a DMZ) and have both the public and private certificates for that SSL/TLS server loaded onto the firewall, and you wish to do an inbound decryption inspection of the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have users trying to visit a website on the internet, you want a forward proxy decryption policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 17:49:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-system-setting-ssl-decrypt-certificate-no-inbound-cert/m-p/237660#M68093</guid>
      <dc:creator>JW6224</dc:creator>
      <dc:date>2018-10-29T17:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: show system setting ssl-decrypt certificate -----No inbound cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-system-setting-ssl-decrypt-certificate-no-inbound-cert/m-p/237661#M68094</link>
      <description>&lt;P&gt;We are using SSL forward Proxy&lt;/P&gt;&lt;P&gt;Seems that info is for the No Inbound Cer================No inbound SSL decrypt?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 17:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-system-setting-ssl-decrypt-certificate-no-inbound-cert/m-p/237661#M68094</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-29T17:53:49Z</dc:date>
    </item>
  </channel>
</rss>

