nerdexam
Palo_Alto_Networks

PCNSE · Question #672

In an HA failover scenario what happens with sessions decrypted by a SSL Forward Proxy Decryption policy?

The correct answer is D. The firewall allows the session but does not decrypt the session. When a failover occurs, the passive device allows transferred sessions without decrypting them. New sessions will then continue to be decrypted based on your decryption policy. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption…

Submitted by wei.xz· Apr 18, 2026Operate

Question

In an HA failover scenario what happens with sessions decrypted by a SSL Forward Proxy Decryption policy?

Options

  • AThe existing session is transferred to the active firewall.
  • BThe firewall drops the session.
  • CThe session is sent to fastpath.
  • DThe firewall allows the session but does not decrypt the session.

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    6% (3)
  • D
    89% (42)

Explanation

When a failover occurs, the passive device allows transferred sessions without decrypting them. New sessions will then continue to be decrypted based on your decryption policy. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption- concepts/decryption-and-high-availability

Topics

#HA Failover#SSL Decryption#Session State#Forward Proxy

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice