<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption in forwarding proxy and a Web proxy after paloalto firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-forwarding-proxy-and-a-web-proxy-after/m-p/293083#M77492</link>
    <description>&lt;P&gt;Well, I think I may have some questions and maybe some answers... &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not familar with a PDL browser... maybe you could help with that question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order for SSL Forward Proxy to work correctly (based on my understanding as instructor), the public cert from the Internet (facebook, bankofamerica, etc) needs to be seen by the outside interface of the FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some sneaky suspicion that the web proxy that you have in front of the FW is causing issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which then asks another question.. if you have PAN-DB, why the need for a Web Proxy, when the firewall can be used to allow/disallow web site traffic, based on URL category.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe you could provide some additional details to help us out. (but step 1... try without the web proxy, if possible... just trying to remove obvious pieces that may causing errors/breakage of traffic)&lt;/P&gt;</description>
    <pubDate>Tue, 15 Oct 2019 18:10:04 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-10-15T18:10:04Z</dc:date>
    <item>
      <title>SSL decryption in forwarding proxy and a Web proxy after paloalto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-forwarding-proxy-and-a-web-proxy-after/m-p/292869#M77458</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;i have a PA firewall used for internet navigation and a transparent proxy for Web navigation.&lt;/P&gt;&lt;P&gt;I have enabled ssl decryption for a specific URL category that i have set in url profile in block-continue.&lt;/P&gt;&lt;P&gt;If i set my PDL browser with the proxy i didn't recive the response page and the connection goes in timeout. If i remove proxy from pdl it works fine.&lt;/P&gt;&lt;P&gt;I set a pcap filter(with paloalto engeener) and we notice that in the different stage:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;firewall: the connection goes well and a RST,ACK at the end of session&lt;/LI&gt;&lt;LI&gt;transmit: the connection goes wrong and a FIN was send from pdl to proxy&lt;/LI&gt;&lt;LI&gt;receive: the connection goes well and a RST,ACK at the end of session&lt;/LI&gt;&lt;LI&gt;drop: no drop&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We have squid as proxy but i didn't find any guide or configuration for this issue. Do you have some ideas:D&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;Gianpiero&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 13:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-forwarding-proxy-and-a-web-proxy-after/m-p/292869#M77458</guid>
      <dc:creator>Gianpiero</dc:creator>
      <dc:date>2019-10-14T13:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption in forwarding proxy and a Web proxy after paloalto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-forwarding-proxy-and-a-web-proxy-after/m-p/293083#M77492</link>
      <description>&lt;P&gt;Well, I think I may have some questions and maybe some answers... &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not familar with a PDL browser... maybe you could help with that question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order for SSL Forward Proxy to work correctly (based on my understanding as instructor), the public cert from the Internet (facebook, bankofamerica, etc) needs to be seen by the outside interface of the FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some sneaky suspicion that the web proxy that you have in front of the FW is causing issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which then asks another question.. if you have PAN-DB, why the need for a Web Proxy, when the firewall can be used to allow/disallow web site traffic, based on URL category.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe you could provide some additional details to help us out. (but step 1... try without the web proxy, if possible... just trying to remove obvious pieces that may causing errors/breakage of traffic)&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 18:10:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-forwarding-proxy-and-a-web-proxy-after/m-p/293083#M77492</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-10-15T18:10:04Z</dc:date>
    </item>
  </channel>
</rss>

