we have PA7050 managed by panorama. We dont have SSL decryption but we want to serve users a block url response page for https traffic. For that I followed following link:
But this doesn't seem to work with 7.1.18.
I have 2 doubts:
1. For the fwd-trust and untrust certificates - I just created them and ticked the approrpiate check box by clicking on the certificates. Do I need to do any additional step?
2. Since I cannot give the command "# set deviceconfig setting ssl-decrypt url-proxy yes" on panorama, I logged on to the FW CLI and then gave this command and then committed from the firewall CLI itself. Is this wrong?