Vigyata.AI
Is this your channel?

#paloaltofirewalltraining | Day 30 | How to configure SSL-Decryption | Detailed Explanation

3.1K views· 50 likes· 26:21· Mar 9, 2025

🛍️ Products Mentioned (2)

Join this channel to get access to perks: https://www.youtube.com/channel/UCBujQdd5rBRg7n70vy7YmAQ/join Hi Friends, Please checkout my new video on How to configure SSL Decryption in Palo Alto. If you like this video give it a thumps up and subscribe my channel for more video. Have any question put it on comment section Recommend Video https://youtu.be/TjtGi7cdhwg Recommend Link (Playlist for EVE-NG LAB Setup) https://www.youtube.com/playlist?list=PLaUiizP3D7fPMmUQqS5QKX_FVSoMP68Z5 Palo Alto Certification information URL: https://www.paloaltonetworks.com/services/education For Palo Alto Documentation https://docs.paloaltonetworks.com/ Please follow me Instagram : https://www.instagram.com/bikashtech Twitter : https://twitter.com/Bikashshaw82 E-mail ID : bikashshaw261@gmail.com #Paloaltotraining ##bikashtech #paloaltofirewalltraining #paloaltonetworks #sslcertificate #ssl

About This Video

Hello friends, welcome to Day 30 of my PCNSA series. In this video I show you the complete, practical way to configure SSL Decryption in Palo Alto—step by step in a simple lab. I start from the basics you actually need in real troubleshooting: how to generate a self-signed certificate on the firewall, what to put in CN (I used my inside interface IP because I don’t have DNS in the lab), and why we use it as a Forward Trust certificate for forward proxy decryption. After that, I create the SSL/TLS Service (SSL Decryption) profile and I explain what those checks mean in real life—certificate expired, untrusted issuer, unsupported cipher/mode, and what to do when the firewall is too busy (fail-open vs fail-close behavior). Then I build the decryption policy (inside to outside), along with the required security policy and NAT, and we commit. Finally, I verify the decryption properly: first you’ll see the browser privacy error because the root CA isn’t installed on the PC. I download/export the cert, install it in Trusted Root (local machine and current user), and then you can see Google/Yahoo certificates being issued by the Palo Alto. In Monitor logs, I enable the “decrypted” column to confirm HTTPS sessions are getting decrypted. I also show the SSL Decryption Exclusion list and why, as per cyber rules, some private apps/sites are excluded by default.

Frequently Asked Questions

🎬 More from Bikash's Tech