- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-28-2025 09:58 AM
Hello,
Would you mind elaborating on your question?
Regards,
04-29-2025 06:42 AM
i am forwarding (BPF) to SkyHigh Web Gateway (on-prem),
SkyHigh Web Gateway has a wonderful solution for identifying (and block) dozens of file-mimes (unlike the short list of Palo Alto file types).
My plan is to to use Palo Alto (as default gateway) content inspection (TP and WF and all the protection modules), and then forward to SkyHigh (2nd hop)
SkyHigh Proxy is listening on port 9090, and gets the traffic.
Both PA and SkyHigh (and clients) using same SSL certificate.
The issue is that the SkyHigh doesn't like the new SSL re-encryption from Palo Alto (1st hop).
Seems like the SSL content inspection doesn't work when traffic comes not directly from clients (SSL is being handled by Palo Alto as MITM)
Ideas?
05-06-2025 10:03 PM
To configure an external web proxy on Palo Alto Networks, choose explicit or transparent mode. Explicit requires client setup, while transparent intercepts traffic.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!