Iristheangel wrote: » Yep. Pretty much resources. Every single firewall out there that does it has a big performance hit. You can create custom rules to decrypt only certain things or maybe like a web server in your DMZ but I don't recommend with ANY vendor to try to do SSL decryption + all the other NGIPS/NGFW/Anti-Malware/etc solutions on the same box. From what I've seen in performance testing on various vendors and in real life, you get pages with PFS and other things and it'll sink your performance. It's better to offload that to dedicated appliance if you absolutely MUST and there's still some legal issues when it comes to decryption of everything (i.e. users visiting their banking sites, SSNs, etc). If you absolutely MUST decrypt, get an appliance dedicated to offloading decryption and also make sure you understand the legal issues of doing so. I would probably try as hard as I can to safely protect at the network level but also harden and make sure endpoints have visibility and are secure.
Iristheangel wrote: » X-Forward works. I've got it running in my lab, sucanushie
MitM wrote: » I've also been running decryption on a number of Palo Alto firewalls (PA-500, PA-3020) with no issues, pretty much for everything except for banking, health, government, shopping. No performance issues so far, but I also think it also depends on the amount of traffic passing through. I know when we looked at CheckPoint, they said no way, you'd have to offload to a different device