- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-17-2014 07:17 AM
Decryption is triggered by Decryption Policies.
Add one and test it out. You can use URL categories if you have URL filtering license to only decrypt specific Web site categories.
SSL forward proxy - outgoing SSL
SSL Inbound - SSL inbound ( if you have a copy of the servers key)
SSH forward proxy - outgoing SSH
Don't forget to generate the certificate needed if you are decrypting outbound connections.
07-17-2014 08:43 AM
Hello Rrau,
Please find below mentioned DOCs, it might help you to understand the basic functionality of SSL decryption and how to implement this on a Palo Alto firewall.
How to Implement SSL Decryption
How to Temporarily Disable SSL Decryption
How to View SSL Decryption Information from the CLI
Difference Between SSL Forward-Proxy and Inbound Inspection Decryption Mode
How to Exclude a Single URL from SSL Decryption
Hope this helps.
Thanks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!