Which THREE statements are true regarding SSL Forward Proxy decryption on Palo Alto Networks firewalls?
Trap 1: SSL Forward Proxy decryption can only be applied to traffic…
It can be applied to other ports as well, though 443 is default.
Trap 2: An 'ssl-decrypt' action in a decryption rule requires that the…
The certificate is configured in the Decryption Profile, but the 'ssl-decrypt' action does not require it; the profile must have a certificate for forward proxy, but it's not the action that requires it.
- A
SSL Forward Proxy decryption can only be applied to traffic destined for TCP port 443.
Why it fails: It can be applied to other ports as well, though 443 is default.
- B
Decryption policy rules can match on source zone, source user, destination IP, URL category, and service.
These are common match criteria for decryption policy rules.
- C
The firewall must generate a certificate on-the-fly signed by a trusted CA for each decrypted session.
This is correct; the firewall acts as a man-in-the-middle and creates a certificate signed by the enterprise CA.
- D
An 'ssl-decrypt' action in a decryption rule requires that the associated decryption profile includes a certificate for the firewall to use.
Why it fails: The certificate is configured in the Decryption Profile, but the 'ssl-decrypt' action does not require it; the profile must have a certificate for forward proxy, but it's not the action that requires it.
- E
The firewall can inspect the Server Name Indication (SNI) field in the ClientHello to determine the destination hostname.
SNI is used for policy matching when decryption is not possible or not required.