pan-os ssl decryption
-ssl/tls sessions can be decrypted and inspected to enforce security policy
decryption types
certificate chain of trust
certificate verification steps
- validate each certificate based on: valid signature, valid expiry date, no malformation or corruption, not revoked
certificate revocation reasons
- failed verification
preferred way to acquire a certificate in pan-os
- have the csr signed by a ca
csr process
certificate deployment option 1
-obtain a signing certificate from a third party ca
certificate deployment option 2
-use an internal ca to issue a signing certificate to the firewall
certificate deployment option 3
-generate a self signing certificate
ssl forward proxy decryption
ssl inbound inspection
ssl inbound inspection unsupported applications
no decryption
wildfire threat intelligence cloud
wildfire markings