Palo Alto SSL Forward Proxy (Outbound SSL Decryption) [2024]

  Рет қаралды 6,800

NETSums

NETSums

Күн бұрын

Пікірлер: 17
@onurcan9129
@onurcan9129 Жыл бұрын
Thanks a lot for your clarifications
@netsums
@netsums Жыл бұрын
You're welcome, I'm glad you liked the video. :)
@Neur0bit
@Neur0bit 6 ай бұрын
fantastic explanation. thanks for all the effort you put into these videos.
@robertoospina10
@robertoospina10 Жыл бұрын
Awesome
@netsums
@netsums Жыл бұрын
Thank you, I'm glad you liked it. :-)
@irvingcastro9971
@irvingcastro9971 Жыл бұрын
Hello, excellent explanation, my compliments. I would like to see that scenario with an enterprise CA or PKI. Thanks for sharing your knowledge.
@netsums
@netsums Жыл бұрын
Hi. Thank you for the comment. :-) im glad you liked the video. I will keep your suggestion in mind for the next tutorials.
@nxu5107
@nxu5107 8 ай бұрын
Hi Thanks for this. What would happen if there are two firewalls in series, both wanting to decrypt the traffic?
@netsums
@netsums 8 ай бұрын
Hi. The second firewall will consider the first as a client (normal PC, just as a server doesn't know it's communicating with a firewall), and will show its certificate to the first firewall. I hope I could answer your question. :)
@nxu5107
@nxu5107 8 ай бұрын
@@netsums Thank you ever so much for your response. I thought along the same lines. Problem is one firewall will only allow us to export it's root CA cert the other is a Palo. We have to work out the logic to position the firewalls in a way to achieve our goals. Thanks again.
@netsums
@netsums 8 ай бұрын
In my opinion the Palo does a pretty good job identifying apps, like differenciating Google drive/docs uploads and downloads, for example. So I would tend to activate the ssl decryption only on the Palo and not on the other firewall, specially if you have the threat prevention license. But yes, it depends also on how the firewalls are setup in your environment.
@baller15g
@baller15g Жыл бұрын
Everyone fears this. It's always a nightmare to deploy.
@netsums
@netsums Жыл бұрын
That's also my experience. Nowadays most companies need it, but it can be a pain for the administrators. And not all users are very understanding, when something that worked before suddenly stops working. 😊
@priyajayswal6581
@priyajayswal6581 Жыл бұрын
Hey can you make video on how to do segmentation on firewall
@netsums
@netsums Жыл бұрын
Hi. What do you mean exactly? Through zones? Or like using different virtual routers?
@modibosissoko634
@modibosissoko634 3 ай бұрын
Hello is this necessarily authorized to use ssl descryption in the network if yes what are the advantages and disadvantages.thx
@netsums
@netsums 2 ай бұрын
I'm not sure I understand your question. In some countries there are some connections that are not allowed to be decrypted. Each company has its own policies. The advantage of SSL decryption is that the firewall gains more visibility on the traffic.
Network Basics - What is a network? // FREE CCNA 200-301 course
18:44
David Bombal Tech
Рет қаралды 65 М.
SSL, TLS, HTTP, HTTPS Explained
6:31
PowerCert Animated Videos
Рет қаралды 2,6 МЛН
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН
How Strong Is Tape?
00:24
Stokes Twins
Рет қаралды 96 МЛН
Decrypting Decryption (Episode 24) Learning Happy Hour
34:34
Palo Alto Networks LIVEcommunity
Рет қаралды 20 М.
TLS Handshake - EVERYTHING that happens when you visit an HTTPS website
27:59
Practical Networking
Рет қаралды 135 М.
How To Configure SSL Forward Proxy Decryption On The Palo Alto Firewall | PART 8
18:07
Keith Barker - The OG of IT
Рет қаралды 26 М.
How to create a valid self signed SSL Certificate?
25:01
Christian Lempa
Рет қаралды 377 М.
Quick and Easy Local SSL Certificates for Your Homelab!
12:08
Wolfgang's Channel
Рет қаралды 885 М.
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН