- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
In today's digital world, where encryption is all around us, SSL decryption becomes a real superhero in the fight against hidden threats and bolstering network security. Luckily, Palo Alto Networks Next-Generation Firewall comes to the rescue with its powerful SSL decryption capabilities. With these tools, organizations can gain insight into encrypted traffic, spot potential risks, and take proactive measures to keep their network safe and sound. In this Tips & Tricks, I'm going to walk you through the steps of enabling SSL inbound decryption. Let's dive in!
In Forward-Proxy mode, PAN-OS will intercept outbound SSL traffic matched to a decryption policy. The firewall acts as a proxy (Man In The Middle) initiating an SSL session with the destination server. During this process, the firewall presents a certificate signed by an Enterprise CA or third-party CA.
Generate or import SSL/TLS certificates:
Note: If you are using a certificate signed by a third-party CA, will have to import the public AND private key (Key Pair).
Configure decryption policies:
Set up SSL decryption profiles:
Configure SSL decryption rules:
Enable SSL decryption on security policies:
Fine-tune SSL decryption settings:
Monitor and troubleshoot:
There you have it! With SSL decryption on your side, you'll be proactive in protecting your network, detecting potential risks, and keeping your organization safe from ever-evolving cyber threats. Stay vigilant and protect yourself online!
Thanks for reading! @JayGolf out.
@JayGolf , do you know if the SSL Forward Trust cert can be from public CA such as GoDaddy? Or it can only be self-signed and Enterprise CA? Thank you in advance.
On 10.2.x and cannot find this setting. Has this moved?
Fine-tune SSL decryption settings:
If you have 2 Forward trust certs, how do you select. The example is we have a current CA that is going to be shutdown (Win2012) and use a new CA (2022) and want to tell the PA to use the new Forward Trust Cert.