SSL Decryption and Forward decrypted content to WildFire Query

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

SSL Decryption and Forward decrypted content to WildFire Query

L2 Linker

Hi Team,

 

I have below 2 tasks which needs to be closed from PaloAlto Level. Appreciate your quick response.

 

Task 1

 

"1.Configure SSL Forward Proxy for all traffic destined to the Internet"

As per the Best Practices we have to enable ssl Decryption for Internet Traffic for that we have to push Certificate to Domain users but My case we have separate Proxy for http and HTTPs Traffic which is in DMZ Zone so we pushed only Proxy certificate to Clients.

In that case Traffic going via Proxy.

Kindly share the PA Recommendation whether i have to enable again for all clients with PA CA certificate or not.

Kindly confirm how to fix this Task 1.


Task 2

 

"Allow the firewall to forward decrypted content to WildFire. Note that SSL Forward-Proxy must also be enabled and configured for this setting to take effect on inside-to-outside traffic flows"

 

what will happen if i enable this option since i didn't enabled SSL decryption.

 

Kindly confirm how to fix this Task 2.

Yazar Arafath
3 REPLIES 3

L2 Linker

Anyone please respond will be helpful

Yazar Arafath

Cyber Elite
Cyber Elite

@Yasar2020 

1. If you're decrypting traffic you'll need to deploy the Forward Trust certificate to the endpoints so that it's actually trusted, or have your root and intermediate certificates trusted by the clients if using an internal PKI. Depending on how you're proxying traffic you wouldn't necessarily need to deploy it to the client and would only need it on the proxy, but that's dependent on how you have things configured. 

 

2. Nothing. The setting simply enables the firewall to to send decrypted traffic to Wildfire for analysis. If you aren't inspecting traffic what you are enabling has zero effect. 

L2 Linker

Dear BPry,

 

Thanks for your update and really Appreciate .

I Agreed for your second point related to Wildfire Encryption will be no effect.

For 1st step
Traffic flow as below

Internal Domain Users--PA FW---DMZ Proxy---PA FW--Internet.

so we installed only Proxy Certificate to the users.

 

FW Policy:

1st rule

src:internal user dst:proxy with service port

2nd rule

src:proxy dst:internet with service port


Do we really need to enable ssl decryption in this case or not.if yes how can i enable decryption rule

src:inside  dst:outside or    src:inside   dst:dmz

will it make any performance issue or traffic delay. Please confirm.

Yazar Arafath
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!