<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: if  ssl inbound decryption  failed，the session will be block or ？ in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/if-ssl-inbound-decryption-failed-the-session-will-be-block-or/m-p/330103#M83718</link>
    <description>Yes, I agree with your point of view, according to what the article should mean, thank you very much for your reply</description>
    <pubDate>Wed, 27 May 2020 15:27:28 GMT</pubDate>
    <dc:creator>Felixcao</dc:creator>
    <dc:date>2020-05-27T15:27:28Z</dc:date>
    <item>
      <title>if  ssl inbound decryption  failed，the session will be block or ？</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/if-ssl-inbound-decryption-failed-the-session-will-be-block-or/m-p/330012#M83706</link>
      <description>The custtomer want to config ssl inbound decrypaion for internal server。 They do not want this configuration to affect existing web services。 I checked the relevant information, i think the firewall in Inbound Inspection mode, PAN-OS will not act as a proxy with SSL traffic matching the policy. PAN-OS will try to decrypt this SSL traffic 'on-the-fly' by eavesdropping the SSL handshake and using associated Certificate (Key Pair) configured in decryption policy ， so if the firewall decryption failed， should the session be unaffected or blck，drop （Even if this policy actions are allowed） Reference url： &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClV8CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClV8CAK&lt;/A&gt;</description>
      <pubDate>Wed, 27 May 2020 07:25:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/if-ssl-inbound-decryption-failed-the-session-will-be-block-or/m-p/330012#M83706</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2020-05-27T07:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: if  ssl inbound decryption  failed，the session will be block or ？</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/if-ssl-inbound-decryption-failed-the-session-will-be-block-or/m-p/330093#M83717</link>
      <description>&lt;P&gt;If RSA keys are used, the Firewall decrypts on-the-fly, if PFS keys are used the firewall has to use man-in-the-middle like the ssl forwarding proxy.&lt;/P&gt;&lt;P&gt;So from my expirience as long as RSA keys are used the connection opens, no matter if the firewall was able to decrypt it or not, but with PFS keys (DHE,ECDHE) it wont open if decryption fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/decryption/decryption-concepts/ssl-inbound-inspection.html#id8e14546e-d8d9-485b-a936-64119ef7ad61" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/decryption/decryption-concepts/ssl-inbound-inspection.html#id8e14546e-d8d9-485b-a936-64119ef7ad61&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 14:59:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/if-ssl-inbound-decryption-failed-the-session-will-be-block-or/m-p/330093#M83717</guid>
      <dc:creator>Adrian_Moechel</dc:creator>
      <dc:date>2020-05-27T14:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: if  ssl inbound decryption  failed，the session will be block or ？</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/if-ssl-inbound-decryption-failed-the-session-will-be-block-or/m-p/330103#M83718</link>
      <description>Yes, I agree with your point of view, according to what the article should mean, thank you very much for your reply</description>
      <pubDate>Wed, 27 May 2020 15:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/if-ssl-inbound-decryption-failed-the-session-will-be-block-or/m-p/330103#M83718</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2020-05-27T15:27:28Z</dc:date>
    </item>
  </channel>
</rss>

