paloaltonetworks:troubleshooting:decryption
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| paloaltonetworks:troubleshooting:decryption [2020/08/05 13:34] – created bstafford | paloaltonetworks:troubleshooting:decryption [2022/11/23 12:49] (current) – external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Troubleshooting Decryption ====== | ====== Troubleshooting Decryption ====== | ||
| + | ===== decrypt-cert-validation ===== | ||
| + | Remember, if you block users from accessing sites with expired certificates (even if this is just set in the " | ||
| + | |||
| + | Also, remember that if you are doing inbound decryption, the certificate on the Palo needs to match the web server. This means that if the web server has the full certificate chain in the certificate file, the certificate on the firewall used for decryption also needs to have the full certificate chain. | ||
| + | |||
| + | Another problem that can happen with inbound decryption is when the firewall sits between the Internet and an F5 Load Balancer. If the F5 load balancer does SSL termination, | ||
| + | |||
| + | |||
| ===== Supported Ciphers ===== | ===== Supported Ciphers ===== | ||
| In PAN-OS 10.0 you can run the following command to see what ciphers the logs are referring to | In PAN-OS 10.0 you can run the following command to see what ciphers the logs are referring to | ||
| < | < | ||
| < | < | ||
paloaltonetworks/troubleshooting/decryption.1596634463.txt.gz · Last modified: (external edit)
