
6 • PAN-OS 6.1 Release Notes Palo Alto Networks
Features Introduced in PAN-OS 6.1 PAN-OS 6.1 Release Information
Configurable Key Size
for SSL Forward Proxy
Server Certificates
The firewall now supports both 2048-bit RSA keys (with SHA-256 hashing) and 1024-bit
RSA keys (with SHA-1 hashing) for generating the certificates it uses to establish the SSL
Forward Proxy session between itself and the client. This is an extension of the 2048-bit key
support that was already available with SSL decryption. In previous releases, 2048-bit keys
were supported in SSL Inbound Inspection sessions as well as in SSL Forward Proxy
sessions between the firewall and the destination server.
As part of the extended support for 2048-bit keys, the firewall will now by default
dynamically choose the key size to use to establish SSL Forward Proxy sessions with clients,
based on the key size used by the destination server. You can optionally configure a static
key size for SSL Forward Proxy sessions between the firewall and clients regardless of the
key size used by the destination server.
Default profile group and
log forwarding settings
You can now allow new security policies and new security zones to include your
organization’s preferred settings for security profile groups or log forwarding by default.
Create a default security profile group or default log forwarding profile; the default profile
group will be attached to new security policies automatically and the default log forwarding
profile will be selected for new security policies and new security zones automatically. With
a default security profile group and a default log forwarding profile configured, you can quickly
create new security policies and security zones without manually selecting your preferred
settings for log forwarding or a profile group each time. This also allows you to enforce
consistency for other administrators creating new policy rules or zones, by including your
organization’s preferred profile group and log forwarding options in new policies or zones
automatically.
New Management
Feature
Description
Commentaires sur ces manuels