Valid Parameters for SSL Decryption Policies

Scenario Question Recap: When configuring SSL Decryption, what are three valid parameters (match criteria) that can be used in an SSL Decryption policy rule?

SSL Decryption policies on Palo Alto Networks firewalls control which encrypted traffic (SSL/TLS) should be intercepted and decrypted for further inspection (like App-ID and Threat Prevention). Similar to Security Policies, these rules use specific parameters to match traffic.

Valid SSL Decryption Policy Match Criteria

According to Palo Alto Networks documentation, the following are primary parameters you can use to define the match criteria for an SSL Decryption rule:

Using these criteria allows administrators to precisely target which traffic flows should undergo decryption.

📘 Explanation of Correct Options from Scenario

Why Other Options Are Incorrect Match Criteria

1. GlobalProtect HIP (Host Information Profile)

3. App-ID (Application Identification)

(Placeholder: Insert Mermaid diagram image here if available)

✅ Summary: SSL Decryption policies primarily use Zone, IP Address, User, URL Category, and Service/Port information as match criteria. App-ID and HIP profiles are used in other policy types, not directly for matching traffic *to be decrypted*.