An administrator implements a new Decryption policy in Prisma Access to inspect inbound traffic to a public-facing application hosted behind a Prisma Access Public IP. After deployment, users report receiving certificate warning errors. What should the administrator inspect first to resolve the warning?
Trap 1: Check whether the GlobalProtect client version on the user's laptop…
Inbound decryption affects external users browsing to services, not necessarily GlobalProtect mobile users.
Trap 2: Ensure that WildFire analysis is disabled for inbound decrypted…
WildFire analysis does not cause browser certificate warning errors.
Trap 3: Verify the OCSP responder settings under Device > Setup > Sessions.
OCSP verification issues typically manifest as revocation check failures, not primary certificate trust warnings caused by missing server keys.
- A
Check whether the GlobalProtect client version on the user's laptop is up to date.
Why wrong: Inbound decryption affects external users browsing to services, not necessarily GlobalProtect mobile users.
- B
Ensure that WildFire analysis is disabled for inbound decrypted traffic.
Why wrong: WildFire analysis does not cause browser certificate warning errors.
- C
Verify that the correct server certificate and private key are imported into Panorama and bound to the Inbound Decryption rule.
If the firewall does not present the correct server certificate to the client, a trust mismatch warning occurs immediately.
- D
Verify the OCSP responder settings under Device > Setup > Sessions.
Why wrong: OCSP verification issues typically manifest as revocation check failures, not primary certificate trust warnings caused by missing server keys.