<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forward traffic inspection in Palo alto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/336127#M84692</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have always been a big believer in keeping things simple. Yes your traffic will take a hit due to the two layers of decryption. However&lt;/P&gt;
&lt;P&gt;&amp;nbsp;there is no need with a properly configured Palo Alto to have another firewall inline. That said, the users machines are the ones that need to trust the certificates of the traffic that is being decrypted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2020 18:40:09 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2020-06-30T18:40:09Z</dc:date>
    <item>
      <title>Forward traffic inspection in Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/335774#M84634</link>
      <description>&lt;P&gt;Palo Alto and Fortinet are configured as internet edge firewalls.&lt;/P&gt;&lt;P&gt;Dual layers FA Internet ---- Palo Alto ------- Fortigate -------- Trust zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Outbound traffic is SSL inspected by a Fortinet firewall and the firewall acts as a forward proxy.&amp;nbsp; All users are using Fortigate certificates in browser-trusted location.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo alto is configured before FortiGate,&lt;/P&gt;&lt;P&gt;Now Palo alto further inspected the SSL traffic which is coming from Fortinet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the above case, what can we do to establish the trust from Palo to Forti? Or can I generate the CA certificate from Palo alto and install in Fortigate in this way traffic further inspected in Palo alto? Or do you need to configure SSL forward proxy and generate the intermediate certificate from Palo alto and install it in FortiGate?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 07:43:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/335774#M84634</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-29T07:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Forward traffic inspection in Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/335948#M84652</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Wait a minute, you're performing SSL inspection on both boxes? That would have a fairly noticeable performance hit, and you would have little to gain inspecting the traffic again on the Fortigate firewall when it's already being inspecting by your PAN firewalls. Statistics wise, you are inspecting that traffic with a product which is continuously rated higher for malicious traffic detection prior to sending it for additional inspection by an inferior signature engine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You're going to need to install whatever certificate you are using on both firewalls, on both firewalls. The PAN is going to need to trust the Fortigate CA and the Fortigate is going to need to trust the PAN. In all honesty though, this isn't something I would even attempt to get to work. Pick one box to perform inspection on, and turn the other SSL Inspection engine off. I would personally recommend keeping decryption enabled on the PAN and disabling decryption on the Fortigate, but you should only have one enabled.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 03:00:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/335948#M84652</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-30T03:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Forward traffic inspection in Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/335991#M84665</link>
      <description>&lt;P&gt;Thank you for your explanation and cooperation&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;My actual question,&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The outbound traffic from the Inside to the internet (the end-user is using FortiGate certificates in browser-trusted location)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;currently, Fortinet is doing the SSL Inspection and acts as a forward proxy for the user internet traffic.&lt;/LI&gt;&lt;LI&gt;Palo alto as a parameter firewall that acts as transparent for the Fortinet inspected Traffics (means current PA doesn’t Inspect the received traffic it’s just forward the received traffic from Fortinet firewall. )&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Expectation, as users, brings the Fortinet certificate to browse the trusted sites. &lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The Palo alto to inspect the SSL traffic too, whichever comes from Fortinet firewall,&lt;/LI&gt;&lt;LI&gt;That means users bring the Fortinet certificate from the trust LAN to browse the internet and the Fortinet firewalls perform the SSL Inspection as the first stage level, then it's forward to PA for SSL inspection as a second stage.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In short, I am looking for that, Palo alto to do the SSL inspection with the Fortinet certificate which is already inspecting by the Fortinet FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise me... its achievable or its the right way to do inspection with box.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 09:36:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/335991#M84665</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-30T09:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Forward traffic inspection in Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/336127#M84692</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have always been a big believer in keeping things simple. Yes your traffic will take a hit due to the two layers of decryption. However&lt;/P&gt;
&lt;P&gt;&amp;nbsp;there is no need with a properly configured Palo Alto to have another firewall inline. That said, the users machines are the ones that need to trust the certificates of the traffic that is being decrypted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 18:40:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/336127#M84692</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-06-30T18:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Forward traffic inspection in Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/336215#M84697</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe, decryption broker option can be helpful.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/decryption/decryption-broker" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/decryption/decryption-broker&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 05:32:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forward-traffic-inspection-in-palo-alto/m-p/336215#M84697</guid>
      <dc:creator>upelister</dc:creator>
      <dc:date>2020-07-01T05:32:51Z</dc:date>
    </item>
  </channel>
</rss>

