Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A company is using a Palo Alto Networks firewall with SSL decryption enabled. Users are reporting certificate warnings when accessing certain internal applications that use self-signed certificates. External websites are not presenting these warnings. What is the most appropriate action to resolve this specific issue for internal applications?

  1. AImport the internal application's self-signed certificate into the firewall's trusted root store and configure a 'No Decrypt' policy.
  2. BImport the internal application's root CA certificate into the firewall's trusted root store.
  3. CInstall the firewall's Forward Trust certificate on user workstations.
  4. DDisable SSL decryption for the internal application traffic.
Show answer & explanation

Correct answer: B. Import the internal application's root CA certificate into the firewall's trusted root store.

When the firewall performs SSL decryption on traffic to internal applications using self-signed certificates, it acts as a man-in-the-middle. If the firewall doesn't trust the internal application's certificate, it will generate a warning. Importing the internal application's root CA (or the self-signed certificate itself if it's acting as its own CA) into the firewall's trusted root store allows the firewall to validate the server's certificate, preventing it from generating a warning when re-signing the traffic with its own Forward Trust certificate.

Why the other options are wrong

  • A. A 'No Decrypt' policy would prevent decryption altogether, bypassing security, and importing the certificate to the firewall's trusted root store is done for *decrypted* traffic to be trusted, not for 'No Decrypt' traffic.
  • C. Installing the firewall's Forward Trust certificate on workstations is for trusted *external* sites that the firewall is decrypting, not for the firewall to trust *internal* server certificates.
  • D. Disabling decryption would resolve the certificate warning but would also bypass security inspection for that traffic, which is generally undesirable.

Decryption Internal Cert Trust

For SSL decryption to work seamlessly with internal applications using self-signed certificates, the Palo Alto Networks firewall must trust those certificates.

  • Firewall acts as a proxy during decryption.
  • Must validate server certificate before re-signing.
  • Importing the server's root CA to the firewall's trusted store resolves warnings.

Memory trick: Decryption needs Trust, both Ways for Warnings to Cease.

More Troubleshoot questions