- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
12-29-2021 09:41 AM
Hi Team,
I have below 2 tasks which needs to be closed from PaloAlto Level. Appreciate your quick response.
Task 1
"1.Configure SSL Forward Proxy for all traffic destined to the Internet"
As per the Best Practices we have to enable ssl Decryption for Internet Traffic for that we have to push Certificate to Domain users but My case we have separate Proxy for http and HTTPs Traffic which is in DMZ Zone so we pushed only Proxy certificate to Clients.
In that case Traffic going via Proxy.
Kindly share the PA Recommendation whether i have to enable again for all clients with PA CA certificate or not.
Kindly confirm how to fix this Task 1.
Task 2
"Allow the firewall to forward decrypted content to WildFire. Note that SSL Forward-Proxy must also be enabled and configured for this setting to take effect on inside-to-outside traffic flows"
what will happen if i enable this option since i didn't enabled SSL decryption.
Kindly confirm how to fix this Task 2.
12-30-2021 08:37 AM
Anyone please respond will be helpful
12-30-2021 12:17 PM
1. If you're decrypting traffic you'll need to deploy the Forward Trust certificate to the endpoints so that it's actually trusted, or have your root and intermediate certificates trusted by the clients if using an internal PKI. Depending on how you're proxying traffic you wouldn't necessarily need to deploy it to the client and would only need it on the proxy, but that's dependent on how you have things configured.
2. Nothing. The setting simply enables the firewall to to send decrypted traffic to Wildfire for analysis. If you aren't inspecting traffic what you are enabling has zero effect.
12-31-2021 09:48 PM
Dear BPry,
Thanks for your update and really Appreciate .
I Agreed for your second point related to Wildfire Encryption will be no effect.
For 1st step
Traffic flow as below
Internal Domain Users--PA FW---DMZ Proxy---PA FW--Internet.
so we installed only Proxy Certificate to the users.
FW Policy:
1st rule
src:internal user dst:proxy with service port
2nd rule
src:proxy dst:internet with service port
Do we really need to enable ssl decryption in this case or not.if yes how can i enable decryption rule
src:inside dst:outside or src:inside dst:dmz
will it make any performance issue or traffic delay. Please confirm.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!