- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-27-2013 06:52 AM
Hi,
This commit error: "Warning: vsys1 decryption: forward decrypt untrust cert is not configured, forward decrypt trust cert will be used instead." Means, that i must generate "Forward untrust certificate" or what?
08-27-2013 06:54 AM
Yes, you need to generate/import a CA cert on the PA and designate it as "Forward untrust cert" if you configure outbound SSL proxy as shown in the screenshot.
08-27-2013 06:56 AM
Good Morning,
Its recommended that the users are presented with a forward untrust certificate, if the server certificate of the web site that the user browses for isnt part of the Trusted CA certificates in the firewall. This is to let the customer know that the website in question is not trusted or safe. Usually the PANFW has most of the CA certificates under its list, and for the ones that are not present, the PANFW considers them as being unsafe.
When configured with the forwared untrust certificate, the user can come to know that the website in question not a safe website
08-27-2013 04:07 PM
Here is a doc which explains on how the different Decryptions (Inbound, outbound, forward proxy) is done on the firewall and general guidlines on how to configure it
https://live.paloaltonetworks.com/docs/DOC-1412
Here are few other useful docs for SSL decryption
https://live.paloaltonetworks.com/docs/DOC-2008
https://live.paloaltonetworks.com/docs/DOC-2006
Hope this helps.
Thanks
Numan
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!