Palo Alto Networks Certified Network Security Engineer (PCNSE) — Question 397
An organization is interested in migrating from their existing web proxy architecture to the Web Proxy feature of their PAN-OS 11.0 firewalls. Currently, HTTP and SSL requests contain the destination IP address of the web server and the client browser is redirected to the proxy.
Which PAN-OS proxy method should be configured to maintain this type of traffic flow?
Answer options
- A. SSL forward proxy
- B. Explicit proxy
- C. Transparent proxy
- D. DNS proxy
Correct answer: C
Explanation
The Transparent proxy method is the correct choice as it allows the traffic to flow without requiring any configuration changes on the client's browser, maintaining the original destination IP. The SSL forward proxy and Explicit proxy methods would require additional configuration on client devices, while the DNS proxy is not relevant to the HTTP and SSL traffic flow described.