Learned something new from you today.
We are going to enable SSL decryption for Inbound traffic coming from Internet to our web servers.
Need to know when does PA intercept the traffic coming form Internet to the web server which is hosting the website?
During 3 way TCP handshake or when first Data packet comes?
This is one of my favorite questions, because the answer is truly that it depends on the type of connection.
For RSA keys, the firewall is able to inspect the traffic without terminating the connection. As the connection crosses the firewall it's going to make a copy of the session and decrypt it so the firewall can apply the appropriate policy to the traffic.
For PFS keys using DHE or ECDHE, the firewall has to proxy the connection between the client and the server. Due to the way the key is generated, we can't transparently sit in that connection even with the certificate and the private key installed. So the firewall is going to create a connection from the client to the firewall, and the firewall to the server to proxy that connection.
If the Connection is using RSA keys then we should not see checked decrypted flag under traffic logs right?
And when the connection is using DHE we should see decrypted flag checked under the traffic logs right?
So this way we can see if connection is RSA or DHE right?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The Live Community thanks you for your participation!