Palo Alto Networks NGFW-Engineer Exam - Topic 2 Question 26 Discussion
An administrator enables SSL Forward Proxy decryption using a self-signed certificate on a Palo Alto Networks firewall as the forward trust certificate. Shortly after, users report receiving "Your connection is not private" browser errors for all external websites.What is the most likely cause of these widespread certificate errors?
D) The firewall's self-signed CA certificate is not deployed to the trusted certificate store on client endpoints.
A) The decryption policy is configured with a 'no-decrypt' action, which causes browsers to reject the connection.
B) The external websites are using TLS 1.3, which cannot be decrypted by the firewall without a specific license.
C) The firewall's forward untrust certificate has expired, preventing it from identifying untrusted sites.
Currently there are no comments in this discussion, be the first to comment!