A network administrator is configuring a new Palo Alto Networks firewall and observes that the dataplane CPU utilization is consistently high, even under moderate traffic load. Upon inspection, it's discovered that the firewall is performing decryption on all traffic, including streaming video and large file transfers, which are not security-sensitive but consume significant resources. Which decryption policy rule modification would most effectively reduce dataplane CPU utilization without compromising security for critical applications?
- AChange the decryption type from 'SSL Forward Proxy' to 'SSL Inbound Inspection'.
- BDisable decryption entirely on the firewall.
- CSet the decryption profile to 'no-decrypt' for all traffic.
- DCreate a 'no-decrypt' rule for streaming video and large file transfer applications, placed above other decryption rules.
Show answer & explanationAnswer & explanation
Correct answer: D. Create a 'no-decrypt' rule for streaming video and large file transfer applications, placed above other decryption rules.
To reduce CPU utilization from decryption while maintaining security for critical applications, it's best to selectively decrypt. Creating a 'no-decrypt' rule for high-bandwidth, non-security-sensitive applications like streaming video and large file transfers, and placing it higher in the policy order, ensures these specific traffic types bypass decryption, saving resources. Other traffic can still be decrypted by subsequent rules.
Why the other options are wrong
- A. Changing to 'SSL Inbound Inspection' is for inspecting traffic to internal servers, not outbound user traffic, and does not address the issue of high CPU for streaming/file transfers.
- B. Disabling decryption entirely would severely compromise security posture by allowing encrypted threats to pass uninspected.
- C. Setting 'no-decrypt' for all traffic would compromise security by not inspecting any encrypted traffic, which is not the goal.
Selective Decryption
Selective decryption involves configuring decryption policies to only decrypt traffic that requires security inspection, thereby optimizing firewall performance and resource utilization.
- Use 'no-decrypt' rules for non-sensitive, high-bandwidth traffic.
- Policy order is crucial for decryption rules.
- Helps manage CPU load and maintain privacy for certain traffic.
Memory trick: Decrypt Smartly: Skip High-Bandwidth, Prioritize Security.