Decrypts SSH traffic for inspection.
Why this answer
SSH Proxy is a valid method for decrypting SSL/TLS traffic on a Palo Alto Networks firewall because it allows the firewall to act as a man-in-the-middle for SSH connections, decrypting the SSH tunnel to inspect the encapsulated traffic. This is distinct from SSL/TLS decryption but is grouped under the same decryption feature set for inspecting encrypted protocols.