Define protocol versions, algorithms, certificate verification, and other settings in
a decryption profile for traffic meeting the criteria in associated decryption policy
rules.
| Where Can I Use
This? | What Do I Need? |
|
|
No separate license required for decryption when using NGFWs or
Prisma Access.
Note: The features and capabilities available to you in
Strata Cloud Manager depend on your active license(s).
|
Configure a
decryption profile to define TLS handshake settings or
session controls for traffic that you decrypt or intentionally
exclude from decryption. Decryption
profiles enable granular control over decrypted and nondecrypted sessions, so you
can tailor decryption policy rules to meet security and compliance requirements.
After you apply a decryption profile to
decryption policy rules, the
Next-Generation Firewall (
NGFW) enforces the profile settings on
traffic matching all the criteria in the rule.
Each type of decryption profile has different settings to configure.
SSL/TLS Decryption Profile (SSL
Forward Proxy and SSL Inbound Inspection)—Use to specify supported TLS
versions and cipher suites, block sessions based on checks for unsupported
modes, session failure, and certificate validity, and configure additional
settings.
Starting
in PAN-OS 12.1.2, you can enable post-quantum cryptography (PQC) algorithms
for TLSv1.3 sessions.
No-Decryption Profile—Use to verify
server certificates and certificate issuer trustworthiness for traffic that
bypass decryption for
compliance, legal, and nontechnical
reasons and refuse connections to servers with expired or
untrusted certificates. This mitigates the risk of users connecting to
malicious or questionable. Apply these profiles only to decryption policy
rules with a no-decrypt action.
TLSv1.3 encrypts certificates during the TLS handshake, preventing the
NGFW from blocking TLSv1.3 sessions based on
certificate information. As a result, applying a no-decryption profile
that only supports TLSv1.3 to a no-decryption policy rule has no
functional effect beyond the logging provided by the policy rule itself.
For no-decryption profiles that support other TLS versions including
TLSv1.3, the NGFW only enforces certificate checks for
TLSv1.2 and earlier sessions but logs all sessions.
SSH Proxy Profile—Use to block sessions based on
checks for unsupported modes and session failures.
If an NGFW is in FIPS-CC mode and managed by a Panorama™
management server in standard mode, a decryption profile must be created locally
on the NGFW. Decryption profiles created on Panorama in standard
mode contain references to the 3DES and
RC4 encryption algorithms and the
MD5 authentication algorithm that aren't supported
and cause pushes to managed NGFWs to fail.