- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-05-2025 04:54 PM
Hello @N.MANTUA
yes, this is correct understanding. Once Exchange server administrator renews certificate you will have to export that certificate from server and import it to Firewall to ensure inbound decryption works after server certificate renewal.
Here is video tutorial for setup of inbound SSL decryption: Video Tutorial: How to Configure SSL Inbound Inspection on the Palo Alto Networks Firewall.
After you have certificate imported in Firewall you can easily replace certificate by selecting it from drop down list under: Options > Certificate. Alternatively if you can have certificate in advance you can pre-prepare by cloning existing decryption policy and use new certificate, then you can position the policy below existing one and flip the order after server admin renews certificate.
Kind Regards
Pavel