Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureHard

A security auditor requires that all encrypted web traffic (SSL/TLS) passing through the Palo Alto Networks firewall must be inspected for threats and vulnerabilities. Users complain about certificate warnings when accessing certain websites after decryption is enabled. Which aspect of decryption configuration is MOST likely causing these user complaints?

  1. AThe decryption policy is set to 'no-decrypt' for specific categories.
  2. BThe application-override policy is incorrectly configured, leading to decryption bypass.
  3. CThe firewall is configured for SSL Inbound Inspection instead of SSL Forward Proxy.
  4. DThe firewall's root CA certificate is not trusted by the client browsers.
Show answer & explanation

Correct answer: D. The firewall's root CA certificate is not trusted by the client browsers.

When SSL Forward Proxy decryption is enabled, the firewall acts as a man-in-the-middle, re-signing server certificates with its own root CA. If this firewall's root CA certificate is not installed and trusted by client browsers, users will receive certificate warnings.

Why the other options are wrong

  • A. If 'no-decrypt' is set, those sites would not be decrypted, and users wouldn't see warnings related to the firewall's decryption process.
  • B. An application-override policy would bypass App-ID, but wouldn't directly cause certificate warnings if traffic is still being decrypted (or not decrypted, in which case there are no warnings).
  • C. SSL Inbound Inspection is for protecting internal servers, not for decrypting outbound user traffic to external websites (which is SSL Forward Proxy). This confusion wouldn't directly cause client certificate warnings for outbound traffic.

SSL Forward Proxy Decryption

A Palo Alto Networks feature that decrypts outbound SSL/TLS traffic from internal clients to external servers, allowing for full security inspection.

  • Firewall acts as a man-in-the-middle.
  • Requires the firewall's root CA certificate to be trusted by clients.
  • Re-signs server certificates with its own CA.
  • Enables inspection of encrypted content for threats.

Memory trick: Decrypt's the key, but certs must agree, or warnings you'll see!

More Deploy and Configure questions