PCNSE · Question #770
Which rule type controls end user SSL traffic to external websites?
The correct answer is C. SSL Forward Proxy. SSL Forward Proxy decryption is the rule type used to inspect encrypted SSL/TLS traffic from internal users destined for external websites.
Question
Which rule type controls end user SSL traffic to external websites?
Options
- ASSL Inbound Inspection
- BSSH Proxy
- CSSL Forward Proxy
- DSSL Outbound Proxyless Inspection
How the community answered
(39 responses)- A8% (3)
- B3% (1)
- C87% (34)
- D3% (1)
Why each option
SSL Forward Proxy decryption is the rule type used to inspect encrypted SSL/TLS traffic from internal users destined for external websites.
SSL Inbound Inspection is used for decrypting and inspecting SSL traffic that is destined for internal servers within the protected network, not for outbound user traffic.
SSH Proxy is a feature designed for decrypting and inspecting SSH (Secure Shell) traffic, which is distinct from SSL/TLS web traffic.
SSL Forward Proxy decryption intercepts and decrypts outbound SSL/TLS traffic initiated by internal users accessing external websites. The firewall acts as an intermediary, generating a new certificate for the destination site to allow full inspection of the encrypted payload.
'SSL Outbound Proxyless Inspection' is not a standard or recognized rule type for decrypting and inspecting outbound SSL traffic on Palo Alto Networks firewalls; the correct term for proxying is SSL Forward Proxy.
Concept tested: SSL Forward Proxy decryption
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/decryption-concepts/ssl-forward-proxy-decryption.html
Topics
Community Discussion
No community discussion yet for this question.