Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium
A network administrator needs to inspect encrypted traffic for threats without requiring client-side certificate installation. Which decryption method should be configured on the Palo Alto Networks firewall?
- ASSL Inbound Inspection
- BSSL Passthrough
- CSSL Forward Proxy Decryption
- DSSH Decryption
Show answer & explanationAnswer & explanation
Correct answer: A. SSL Inbound Inspection
SSL Inbound Inspection (also known as SSL Decryption for server-side traffic) is used to decrypt traffic destined for internal servers. It requires the firewall to have the server's private key, but no client-side certificate installation is needed for the internal clients accessing that server.
Why the other options are wrong
- B. SSL Passthrough means no decryption occurs, which doesn't meet the requirement to inspect encrypted traffic.
- C. SSL Forward Proxy Decryption decrypts client-initiated outbound traffic and requires a trusted root CA certificate on the clients.
- D. SSH Decryption is for Secure Shell traffic, not general SSL/TLS web traffic.
SSL Inbound Inspection (Server Decryption)
A decryption method used to inspect encrypted traffic destined for internal servers protected by the firewall. It requires the firewall to possess the private key of the server's certificate.
- Used for traffic flowing to internal servers.
- Requires the server's private key on the firewall.
- No client-side certificate installation is needed for internal clients.
Memory trick: Inbound is for the server, Forward is for the client's journey out.