Firewall do Zero #4 SSL Decryption no Palo Alto com AD CS CA do Windows na Prática

In this #4 lesson of the "Firewall from Scratch" series, we configure SSL Decryption on Palo Alto using the Windows AD (Active Directory Certificate Services) CA to sign certificates presented to domain clients. What you will see, from start to finish: How certificates work in Palo Alto: Forward Trust vs. Forward Untrust (when each is used). Importing the Root CA from AD and generating a Sub-CA certificate in the firewall for Forward Trust. Creating a second certificate for Forward Untrust. Decryption Policy (Outbound) and SSL Decryption Profile with best practices: blocking untrusted issuers, self-signed/auto-sign certificates, expired certificates, etc. Test on a Windows machine already on the domain: we access websites with and without decryption and compare the certificate in the browser. Demonstration on badssl.com showing the firewall acting and blocking according to the profile. Topics to navigate: 00:00 Intro 00:55 Lab Changes 01:40 Windows Certificate 02:45 Explaining Decryption 04:00 Showing Paloalto 05:00 Importing a certificate from AD 07:30 Generating a CSR certificate in Paloalto 08:59 Signing a CSR certificate in AD 10:44 Importing a signed CSR certificate 11:27 Setting the certificate as Decryption 11:47 Creating a BAD certificate 13:10 Decryption Profile 14:00 Decryption Policy 15:10 Checking a Windows connection without decryption 17:30 Commit 18:30 Checking a Windows connection with decryption 20:00 Testing an insecure website 21:00 What we will do in the next classes 21:30 Leave a like, guys! If this video helped you in any way, consider leaving a like! Thank youuu

I tested Palo Alto's AntiVirus: EICAR, Logs, and the Role of SSL Decryption (in practice).
▶︎

I tested Palo Alto's AntiVirus: EICAR, Logs, and the Role of SSL Decryption (in practice).

How to configure DoS Protection in Palo Alto (ICMP Flood in Kali Linux)
▶︎

How to configure DoS Protection in Palo Alto (ICMP Flood in Kali Linux)

Crash Course, Active Directory, DHCP & DNS for Entry Level Tech Support
▶︎

Crash Course, Active Directory, DHCP & DNS for Entry Level Tech Support

Palo Alto HA + Cisco NxOS vPC: Aggregate Ethernet Configuration (LACP) and Failover
▶︎

Palo Alto HA + Cisco NxOS vPC: Aggregate Ethernet Configuration (LACP) and Failover

Firewall do Zero #0: Apresentação, fundamentos, bloqueios, modelos e features
▶︎

Firewall do Zero #0: Apresentação, fundamentos, bloqueios, modelos e features

Palo Alto: Auto-blocking malicious IPs with Tags + Dynamic Address Groups (DAG)
▶︎

Palo Alto: Auto-blocking malicious IPs with Tags + Dynamic Address Groups (DAG)

Elfenbeinküste – Ecuador Highlights | Gruppe E, FIFA WM 2026 | sportstudio
▶︎

Elfenbeinküste – Ecuador Highlights | Gruppe E, FIFA WM 2026 | sportstudio

Niederlande – Japan Highlights | Gruppe F, FIFA WM 2026 | sportstudio
▶︎

Niederlande – Japan Highlights | Gruppe F, FIFA WM 2026 | sportstudio

Jfrog | Jfrog Artifactory | Jfrog Artifactory Tutorial | Artifactory Tutorial | Intellipaat
▶︎

Jfrog | Jfrog Artifactory | Jfrog Artifactory Tutorial | Artifactory Tutorial | Intellipaat

But what is the Fourier Transform?  A visual introduction.
▶︎

But what is the Fourier Transform? A visual introduction.

How to Configure BGP on Palo Alto (2 Firewalls) + Route Table and Logs - 2026
▶︎

How to Configure BGP on Palo Alto (2 Firewalls) + Route Table and Logs - 2026

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!
▶︎

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!

Palo Alto Firewall: How to Automate Bulk Configurations via CLI
▶︎

Palo Alto Firewall: How to Automate Bulk Configurations via CLI

Wireshark Tutorial for Beginners | Network Scanning Made Easy
▶︎

Wireshark Tutorial for Beginners | Network Scanning Made Easy

EMPIEZA EL JUEVES CON FE | HOY DIOS TE DA PROTECCIÓN Y PAZ PARA TU FAMILIA | PADRE FREDDY BUSTAMANTE
▶︎

EMPIEZA EL JUEVES CON FE | HOY DIOS TE DA PROTECCIÓN Y PAZ PARA TU FAMILIA | PADRE FREDDY BUSTAMANTE

Firewall Fundamentals Explained | Network Security for Beginners
▶︎

Firewall Fundamentals Explained | Network Security for Beginners

Docker Tutorial for Beginners [FULL COURSE in 3 Hours]
▶︎

Docker Tutorial for Beginners [FULL COURSE in 3 Hours]

QoS on Palo Alto: Policy classifies, but it only works if you do this on the Interface
▶︎

QoS on Palo Alto: Policy classifies, but it only works if you do this on the Interface

Microsoft Just Released Their Own Linux Distro: Should You Be Worried?
▶︎

Microsoft Just Released Their Own Linux Distro: Should You Be Worried?

Old Stone Bridge River Town | 4K Vintage Art Screensaver Frame TV
▶︎

Old Stone Bridge River Town | 4K Vintage Art Screensaver Frame TV