SSL Decryption
Traffic that has been encrypted using the protocols SSL and SSH can be decrypted to ensure that these protocols are being used for the intended purposes only, and not to conceal unwanted activity or malicious content.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

SSL Decryption

Traffic that has been encrypted using the protocols SSL and SSH can be decrypted to ensure that these protocols are being used for the intended purposes only, and not to conceal unwanted activity or malicious content.

Palo Alto Networks firewalls decrypt encrypted traffic by using keys to transform strings (passwords and shared secrets) from ciphertext to plaintext (decryption) and from plaintext back to ciphertext (re-encrypting traffic as it exits the device).

Discussions

Author Topic Views Replies
SBSK-Engine
01-07-2025

Broker VM rejects SSL certificate

Hello PAN community, I am trying to import a SSL certificate into our #BrokerVMI can upload the private key, but the Server Certificate gets rejecte... — Read more

posted in General Topics

63 0
TonyDeHart
01-06-2025

GlobalProtect SSL Cert change take effect immediately or require new GP session login?

If I update an existing certificate for GlobalProtects Portal and Gateway does anyone know if that certificate change impacts existing already running... — Read more

posted in GlobalProtect Discussions

78 0
Han.Valk
01-07-2025

For those that seek to get SSH Proxy working

Searching the internet it seems that people are looking to enable SSH Proxy and not finding answers. I managed to get it working but must say that the... — Read more

posted in General Topics

172 1
vishnusj1810
01-04-2025

Security policy not matching for CP authenticated LDAP users

Objective: Configure Captive portal for non-windows users to authenticate, but use AD credentials through LDAP authentication. Configuration performe... — Read more

posted in Next-Generation Firewall Discussions

57 0
GWong4
01-06-2025

Palo Alto Firewall Global Protect SSL VPN MFA OKTA Integration

Hello Community, I'm looking into integrating Okta's Multi-Factor Authentication (MFA) with GlobalProtect SSLVPN. May I know is the OKTA MFA is free... — Read more

posted in Next-Generation Firewall Discussions

153 3

Blogs

DOTW: What Are Cipher Suites?

01-06-2022 — Find out what are cipher suites and which ones are supported for the different features on your device in this Discussion of the Week. Find out what are cipher suites and which ones are supported for the different features on your device in this D... — Read more

Labels: Administration Decryption How to SSL SSL Decryption tls
5786 3 by in Community Blogs

The Increasing Necessity for SSL Decryption

07-07-2021 — From performance abilities to new hardware, SSL Decryption capabilities have been greatly improved. — Read more

Labels: ngfw SSL Decryption
8323 6 by in Community Blogs

More on SSL Decryption

08-07-2020 — Read how SSL Decryption gives the ability to view inside of Secure HTTP traffic (SSL) as it passes through the Palo Alto Networks firewall. — Read more

Labels: NGFW Configuration PAN-OS SSL Decryption SSL Forward Proxy
21205 3 8 by in Community Blogs

HTTP/2 Inspection

07-09-2020 — Starting with PAN-OS 9.0.0, HTTP/2 inspection is supported on Palo Alto Networks firewalls. Learn more here! — Read more

Labels: Decryption HTTP NGFW Configuration PAN-OS PAN-OS 9.0 SSL Decryption
18068 2 9 by in Community Blogs

AddTrust External CA Root Expired

06-05-2020 — AddTrust External CA Root expired on 30th of May, 2020. Find out how this can impact your traffic and how to fix this! — Read more

Labels: certificate Decryption SSL Decryption
9046 2 2 by in Community Blogs

Articles

Tips & Tricks: SSL Forward Proxy

05-22-2023 — In today's digital world, where encryption is all around us, SSL decryption becomes a real superhero in the fight against hidden threats and bolstering network security. Luckily, Palo Alto Networks Next-Generation Firewall comes to the rescue with... — Read more

Labels: Network Security Next-Generation Firewall SSL Decryption
7247 4 2 by in General Articles

Nominated Discussion: URL Filtering in TLS v1.3

02-28-2023 — — Read more

Labels: Advanced URL Filtering ngfw NGFW Configuration SSL SSL Decryption tls
6356 1 2 by in General Articles

Best Practices for SSL Decryption with Prisma Access

01-13-2022 — Understand how SSL Decryption with Prisma Access can increase your visibility into network traffic and reduce security threats — Read more

Labels: Best Practices prisma access SSL Decryption SSL Forward Proxy
9084 by in Prisma Access Webinars

SSL Decryption with Prisma Access

09-13-2021 — Gain visibility and control over network traffic through SSL Decryption with Prisma Access — Read more

Labels: prisma access SSL Decryption
6212 by in Prisma Access Webinars

Keeping Configuration Aligned to Best Practices

03-31-2021 — Configuration changes are always necessary in a network, whether they are for adding new applications, allowing access to users or to create exceptions in security profiles. Prisma Access Cloud Management provides the ability for administrators to make sure that the configuration is always aligne... — Read more

Labels: Prisma Access Cloud Management SSL Decryption
5441 by in Prisma Access Cloud Management Articles

Videos

Digital Learning Courses

Visit Palo Alto Networks' learning platform, Beacon, for free technical knowledge and educational resources related to all of our products.

Please note: You need to be logged into SSO in order to view this content.