Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium

A network administrator needs to inspect encrypted traffic for threats without requiring client-side certificate installation. Which decryption method should be configured on the Palo Alto Networks firewall?

  1. ASSL Inbound Inspection
  2. BSSL Passthrough
  3. CSSL Forward Proxy Decryption
  4. DSSH Decryption
Show answer & explanation

Correct answer: A. SSL Inbound Inspection

SSL Inbound Inspection (also known as SSL Decryption for server-side traffic) is used to decrypt traffic destined for internal servers. It requires the firewall to have the server's private key, but no client-side certificate installation is needed for the internal clients accessing that server.

Why the other options are wrong

  • B. SSL Passthrough means no decryption occurs, which doesn't meet the requirement to inspect encrypted traffic.
  • C. SSL Forward Proxy Decryption decrypts client-initiated outbound traffic and requires a trusted root CA certificate on the clients.
  • D. SSH Decryption is for Secure Shell traffic, not general SSL/TLS web traffic.

SSL Inbound Inspection (Server Decryption)

A decryption method used to inspect encrypted traffic destined for internal servers protected by the firewall. It requires the firewall to possess the private key of the server's certificate.

  • Used for traffic flowing to internal servers.
  • Requires the server's private key on the firewall.
  • No client-side certificate installation is needed for internal clients.

Memory trick: Inbound is for the server, Forward is for the client's journey out.

More Core Concepts questions