Viewing docs for panos 2.0.12
published on Wednesday, Jun 17, 2026 by paloaltonetworks
published on Wednesday, Jun 17, 2026 by paloaltonetworks
Viewing docs for panos 2.0.12
published on Wednesday, Jun 17, 2026 by paloaltonetworks
published on Wednesday, Jun 17, 2026 by paloaltonetworks
Using getDecryptionProfile
Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.
function getDecryptionProfile(args: GetDecryptionProfileArgs, opts?: InvokeOptions): Promise<GetDecryptionProfileResult>
function getDecryptionProfileOutput(args: GetDecryptionProfileOutputArgs, opts?: InvokeOptions): Output<GetDecryptionProfileResult>def get_decryption_profile(disable_override: Optional[str] = None,
forwarded_only: Optional[bool] = None,
interface: Optional[str] = None,
location: Optional[GetDecryptionProfileLocation] = None,
name: Optional[str] = None,
ssh_proxy: Optional[GetDecryptionProfileSshProxy] = None,
ssl_forward_proxy: Optional[GetDecryptionProfileSslForwardProxy] = None,
ssl_inbound_proxy: Optional[GetDecryptionProfileSslInboundProxy] = None,
ssl_no_proxy: Optional[GetDecryptionProfileSslNoProxy] = None,
ssl_protocol_settings: Optional[GetDecryptionProfileSslProtocolSettings] = None,
opts: Optional[InvokeOptions] = None) -> GetDecryptionProfileResult
def get_decryption_profile_output(disable_override: pulumi.Input[Optional[str]] = None,
forwarded_only: pulumi.Input[Optional[bool]] = None,
interface: pulumi.Input[Optional[str]] = None,
location: pulumi.Input[Optional[GetDecryptionProfileLocationArgs]] = None,
name: pulumi.Input[Optional[str]] = None,
ssh_proxy: pulumi.Input[Optional[GetDecryptionProfileSshProxyArgs]] = None,
ssl_forward_proxy: pulumi.Input[Optional[GetDecryptionProfileSslForwardProxyArgs]] = None,
ssl_inbound_proxy: pulumi.Input[Optional[GetDecryptionProfileSslInboundProxyArgs]] = None,
ssl_no_proxy: pulumi.Input[Optional[GetDecryptionProfileSslNoProxyArgs]] = None,
ssl_protocol_settings: pulumi.Input[Optional[GetDecryptionProfileSslProtocolSettingsArgs]] = None,
opts: Optional[InvokeOptions] = None) -> Output[GetDecryptionProfileResult]func LookupDecryptionProfile(ctx *Context, args *LookupDecryptionProfileArgs, opts ...InvokeOption) (*LookupDecryptionProfileResult, error)
func LookupDecryptionProfileOutput(ctx *Context, args *LookupDecryptionProfileOutputArgs, opts ...InvokeOption) LookupDecryptionProfileResultOutput> Note: This function is named LookupDecryptionProfile in the Go SDK.
public static class GetDecryptionProfile
{
public static Task<GetDecryptionProfileResult> InvokeAsync(GetDecryptionProfileArgs args, InvokeOptions? opts = null)
public static Output<GetDecryptionProfileResult> Invoke(GetDecryptionProfileInvokeArgs args, InvokeOptions? opts = null)
}public static CompletableFuture<GetDecryptionProfileResult> getDecryptionProfile(GetDecryptionProfileArgs args, InvokeOptions options)
public static Output<GetDecryptionProfileResult> getDecryptionProfile(GetDecryptionProfileArgs args, InvokeOptions options)
fn::invoke:
function: panos:index/getDecryptionProfile:getDecryptionProfile
arguments:
# arguments dictionarydata "panos_getdecryptionprofile" "name" {
# arguments
}The following arguments are supported:
- Location
Get
Decryption Profile Location - The location of this object.
- Name string
- Disable
Override string - disable object override in child device groups
- Forwarded
Only bool - mirror after security policy allow
- Interface string
- decrypt mirror port
- Ssh
Proxy GetDecryption Profile Ssh Proxy - Ssl
Forward GetProxy Decryption Profile Ssl Forward Proxy - Ssl
Inbound GetProxy Decryption Profile Ssl Inbound Proxy - Ssl
No GetProxy Decryption Profile Ssl No Proxy - Ssl
Protocol GetSettings Decryption Profile Ssl Protocol Settings
- Location
Get
Decryption Profile Location - The location of this object.
- Name string
- Disable
Override string - disable object override in child device groups
- Forwarded
Only bool - mirror after security policy allow
- Interface string
- decrypt mirror port
- Ssh
Proxy GetDecryption Profile Ssh Proxy - Ssl
Forward GetProxy Decryption Profile Ssl Forward Proxy - Ssl
Inbound GetProxy Decryption Profile Ssl Inbound Proxy - Ssl
No GetProxy Decryption Profile Ssl No Proxy - Ssl
Protocol GetSettings Decryption Profile Ssl Protocol Settings
- location object
- The location of this object.
- name string
- disable_
override string - disable object override in child device groups
- forwarded_
only bool - mirror after security policy allow
- interface string
- decrypt mirror port
- ssh_
proxy object - ssl_
forward_ objectproxy - ssl_
inbound_ objectproxy - ssl_
no_ objectproxy - ssl_
protocol_ objectsettings
- location
Get
Decryption Profile Location - The location of this object.
- name String
- disable
Override String - disable object override in child device groups
- forwarded
Only Boolean - mirror after security policy allow
- interface_ String
- decrypt mirror port
- ssh
Proxy GetDecryption Profile Ssh Proxy - ssl
Forward GetProxy Decryption Profile Ssl Forward Proxy - ssl
Inbound GetProxy Decryption Profile Ssl Inbound Proxy - ssl
No GetProxy Decryption Profile Ssl No Proxy - ssl
Protocol GetSettings Decryption Profile Ssl Protocol Settings
- location
Get
Decryption Profile Location - The location of this object.
- name string
- disable
Override string - disable object override in child device groups
- forwarded
Only boolean - mirror after security policy allow
- interface string
- decrypt mirror port
- ssh
Proxy GetDecryption Profile Ssh Proxy - ssl
Forward GetProxy Decryption Profile Ssl Forward Proxy - ssl
Inbound GetProxy Decryption Profile Ssl Inbound Proxy - ssl
No GetProxy Decryption Profile Ssl No Proxy - ssl
Protocol GetSettings Decryption Profile Ssl Protocol Settings
- location
Get
Decryption Profile Location - The location of this object.
- name str
- disable_
override str - disable object override in child device groups
- forwarded_
only bool - mirror after security policy allow
- interface str
- decrypt mirror port
- ssh_
proxy GetDecryption Profile Ssh Proxy - ssl_
forward_ Getproxy Decryption Profile Ssl Forward Proxy - ssl_
inbound_ Getproxy Decryption Profile Ssl Inbound Proxy - ssl_
no_ Getproxy Decryption Profile Ssl No Proxy - ssl_
protocol_ Getsettings Decryption Profile Ssl Protocol Settings
- location Property Map
- The location of this object.
- name String
- disable
Override String - disable object override in child device groups
- forwarded
Only Boolean - mirror after security policy allow
- interface String
- decrypt mirror port
- ssh
Proxy Property Map - ssl
Forward Property MapProxy - ssl
Inbound Property MapProxy - ssl
No Property MapProxy - ssl
Protocol Property MapSettings
getDecryptionProfile Result
The following output properties are available:
- Disable
Override string - disable object override in child device groups
- Forwarded
Only bool - mirror after security policy allow
- Id string
- The provider-assigned unique ID for this managed resource.
- Interface string
- decrypt mirror port
- Location
Get
Decryption Profile Location - The location of this object.
- Name string
- Ssh
Proxy GetDecryption Profile Ssh Proxy - Ssl
Forward GetProxy Decryption Profile Ssl Forward Proxy - Ssl
Inbound GetProxy Decryption Profile Ssl Inbound Proxy - Ssl
No GetProxy Decryption Profile Ssl No Proxy - Ssl
Protocol GetSettings Decryption Profile Ssl Protocol Settings
- Disable
Override string - disable object override in child device groups
- Forwarded
Only bool - mirror after security policy allow
- Id string
- The provider-assigned unique ID for this managed resource.
- Interface string
- decrypt mirror port
- Location
Get
Decryption Profile Location - The location of this object.
- Name string
- Ssh
Proxy GetDecryption Profile Ssh Proxy - Ssl
Forward GetProxy Decryption Profile Ssl Forward Proxy - Ssl
Inbound GetProxy Decryption Profile Ssl Inbound Proxy - Ssl
No GetProxy Decryption Profile Ssl No Proxy - Ssl
Protocol GetSettings Decryption Profile Ssl Protocol Settings
- disable_
override string - disable object override in child device groups
- forwarded_
only bool - mirror after security policy allow
- id string
- The provider-assigned unique ID for this managed resource.
- interface string
- decrypt mirror port
- location object
- The location of this object.
- name string
- ssh_
proxy object - ssl_
forward_ objectproxy - ssl_
inbound_ objectproxy - ssl_
no_ objectproxy - ssl_
protocol_ objectsettings
- disable
Override String - disable object override in child device groups
- forwarded
Only Boolean - mirror after security policy allow
- id String
- The provider-assigned unique ID for this managed resource.
- interface_ String
- decrypt mirror port
- location
Get
Decryption Profile Location - The location of this object.
- name String
- ssh
Proxy GetDecryption Profile Ssh Proxy - ssl
Forward GetProxy Decryption Profile Ssl Forward Proxy - ssl
Inbound GetProxy Decryption Profile Ssl Inbound Proxy - ssl
No GetProxy Decryption Profile Ssl No Proxy - ssl
Protocol GetSettings Decryption Profile Ssl Protocol Settings
- disable
Override string - disable object override in child device groups
- forwarded
Only boolean - mirror after security policy allow
- id string
- The provider-assigned unique ID for this managed resource.
- interface string
- decrypt mirror port
- location
Get
Decryption Profile Location - The location of this object.
- name string
- ssh
Proxy GetDecryption Profile Ssh Proxy - ssl
Forward GetProxy Decryption Profile Ssl Forward Proxy - ssl
Inbound GetProxy Decryption Profile Ssl Inbound Proxy - ssl
No GetProxy Decryption Profile Ssl No Proxy - ssl
Protocol GetSettings Decryption Profile Ssl Protocol Settings
- disable_
override str - disable object override in child device groups
- forwarded_
only bool - mirror after security policy allow
- id str
- The provider-assigned unique ID for this managed resource.
- interface str
- decrypt mirror port
- location
Get
Decryption Profile Location - The location of this object.
- name str
- ssh_
proxy GetDecryption Profile Ssh Proxy - ssl_
forward_ Getproxy Decryption Profile Ssl Forward Proxy - ssl_
inbound_ Getproxy Decryption Profile Ssl Inbound Proxy - ssl_
no_ Getproxy Decryption Profile Ssl No Proxy - ssl_
protocol_ Getsettings Decryption Profile Ssl Protocol Settings
- disable
Override String - disable object override in child device groups
- forwarded
Only Boolean - mirror after security policy allow
- id String
- The provider-assigned unique ID for this managed resource.
- interface String
- decrypt mirror port
- location Property Map
- The location of this object.
- name String
- ssh
Proxy Property Map - ssl
Forward Property MapProxy - ssl
Inbound Property MapProxy - ssl
No Property MapProxy - ssl
Protocol Property MapSettings
Supporting Types
GetDecryptionProfileLocation
- Device
Group GetDecryption Profile Location Device Group - Located in a specific Device Group
-
Get
Decryption Profile Location Shared - Panorama shared object
- Vsys
Get
Decryption Profile Location Vsys - Located in a specific Virtual System
- Device
Group GetDecryption Profile Location Device Group - Located in a specific Device Group
-
Get
Decryption Profile Location Shared - Panorama shared object
- Vsys
Get
Decryption Profile Location Vsys - Located in a specific Virtual System
- device_
group object - Located in a specific Device Group
- object
- Panorama shared object
- vsys object
- Located in a specific Virtual System
- device
Group GetDecryption Profile Location Device Group - Located in a specific Device Group
-
Get
Decryption Profile Location Shared - Panorama shared object
- vsys
Get
Decryption Profile Location Vsys - Located in a specific Virtual System
- device
Group GetDecryption Profile Location Device Group - Located in a specific Device Group
-
Get
Decryption Profile Location Shared - Panorama shared object
- vsys
Get
Decryption Profile Location Vsys - Located in a specific Virtual System
- device_
group GetDecryption Profile Location Device Group - Located in a specific Device Group
-
Get
Decryption Profile Location Shared - Panorama shared object
- vsys
Get
Decryption Profile Location Vsys - Located in a specific Virtual System
- device
Group Property Map - Located in a specific Device Group
- Property Map
- Panorama shared object
- vsys Property Map
- Located in a specific Virtual System
GetDecryptionProfileLocationDeviceGroup
- Name string
- Device Group name
- Panorama
Device string - Panorama device name
- Name string
- Device Group name
- Panorama
Device string - Panorama device name
- name string
- Device Group name
- panorama_
device string - Panorama device name
- name String
- Device Group name
- panorama
Device String - Panorama device name
- name string
- Device Group name
- panorama
Device string - Panorama device name
- name str
- Device Group name
- panorama_
device str - Panorama device name
- name String
- Device Group name
- panorama
Device String - Panorama device name
GetDecryptionProfileLocationVsys
- Name string
- The Virtual System name
- Ngfw
Device string - The NGFW device name
- Name string
- The Virtual System name
- Ngfw
Device string - The NGFW device name
- name string
- The Virtual System name
- ngfw_
device string - The NGFW device name
- name String
- The Virtual System name
- ngfw
Device String - The NGFW device name
- name string
- The Virtual System name
- ngfw
Device string - The NGFW device name
- name str
- The Virtual System name
- ngfw_
device str - The NGFW device name
- name String
- The Virtual System name
- ngfw
Device String - The NGFW device name
GetDecryptionProfileSshProxy
- Block
If boolNo Resource - whether to block sessions if device has no enough resources
- Block
Ssh boolErrors - whether to block sessions if ssh errors are encountered
- Block
Unsupported boolAlg - whether to block sessions if ssh algorithm is not supported
- Block
Unsupported boolVersion - whether to block sessions if ssh version is not supported
- Block
If boolNo Resource - whether to block sessions if device has no enough resources
- Block
Ssh boolErrors - whether to block sessions if ssh errors are encountered
- Block
Unsupported boolAlg - whether to block sessions if ssh algorithm is not supported
- Block
Unsupported boolVersion - whether to block sessions if ssh version is not supported
- block_
if_ boolno_ resource - whether to block sessions if device has no enough resources
- block_
ssh_ boolerrors - whether to block sessions if ssh errors are encountered
- block_
unsupported_ boolalg - whether to block sessions if ssh algorithm is not supported
- block_
unsupported_ boolversion - whether to block sessions if ssh version is not supported
- block
If BooleanNo Resource - whether to block sessions if device has no enough resources
- block
Ssh BooleanErrors - whether to block sessions if ssh errors are encountered
- block
Unsupported BooleanAlg - whether to block sessions if ssh algorithm is not supported
- block
Unsupported BooleanVersion - whether to block sessions if ssh version is not supported
- block
If booleanNo Resource - whether to block sessions if device has no enough resources
- block
Ssh booleanErrors - whether to block sessions if ssh errors are encountered
- block
Unsupported booleanAlg - whether to block sessions if ssh algorithm is not supported
- block
Unsupported booleanVersion - whether to block sessions if ssh version is not supported
- block_
if_ boolno_ resource - whether to block sessions if device has no enough resources
- block_
ssh_ boolerrors - whether to block sessions if ssh errors are encountered
- block_
unsupported_ boolalg - whether to block sessions if ssh algorithm is not supported
- block_
unsupported_ boolversion - whether to block sessions if ssh version is not supported
- block
If BooleanNo Resource - whether to block sessions if device has no enough resources
- block
Ssh BooleanErrors - whether to block sessions if ssh errors are encountered
- block
Unsupported BooleanAlg - whether to block sessions if ssh algorithm is not supported
- block
Unsupported BooleanVersion - whether to block sessions if ssh version is not supported
GetDecryptionProfileSslForwardProxy
- Auto
Include boolAltname - whether to automatically append SAN to impersonating certificate if server certificate is missing SAN
- Block
Client boolCert - Block sessions with client certificate
- Block
Expired boolCertificate - Block sessions with expired certificates
- bool
- whether to block sessions if HSM is unavailable
- Block
If boolNo Resource - whether to block sessions if device has no enough resources
- Block
If boolSni Mismatch - whether to block a session when certificate's subject name or SAN doesn't match SNI
- Block
Timeout boolCert - Block sessions if certificate status cannot be retrieved within timeout
- Block
Tls13Downgrade boolNo Resource - whether to downgrade from tls1.3 if device has not enough resources
- Block
Unknown boolCert - Block sessions if certificate status is unknown
- Block
Unsupported boolCipher - Block sessions with unsupported cipher suites
- Block
Unsupported boolVersion - Block sessions with unsupported protocol versions
- Block
Untrusted boolIssuer - Block sessions with untrusted certificate issuers
- Restrict
Cert boolExts - Restrict certificate extensions
- Strip
Alpn bool - Strip ALPN extension from ClientHello
- Auto
Include boolAltname - whether to automatically append SAN to impersonating certificate if server certificate is missing SAN
- Block
Client boolCert - Block sessions with client certificate
- Block
Expired boolCertificate - Block sessions with expired certificates
- bool
- whether to block sessions if HSM is unavailable
- Block
If boolNo Resource - whether to block sessions if device has no enough resources
- Block
If boolSni Mismatch - whether to block a session when certificate's subject name or SAN doesn't match SNI
- Block
Timeout boolCert - Block sessions if certificate status cannot be retrieved within timeout
- Block
Tls13Downgrade boolNo Resource - whether to downgrade from tls1.3 if device has not enough resources
- Block
Unknown boolCert - Block sessions if certificate status is unknown
- Block
Unsupported boolCipher - Block sessions with unsupported cipher suites
- Block
Unsupported boolVersion - Block sessions with unsupported protocol versions
- Block
Untrusted boolIssuer - Block sessions with untrusted certificate issuers
- Restrict
Cert boolExts - Restrict certificate extensions
- Strip
Alpn bool - Strip ALPN extension from ClientHello
- auto_
include_ boolaltname - whether to automatically append SAN to impersonating certificate if server certificate is missing SAN
- block_
client_ boolcert - Block sessions with client certificate
- block_
expired_ boolcertificate - Block sessions with expired certificates
- bool
- whether to block sessions if HSM is unavailable
- block_
if_ boolno_ resource - whether to block sessions if device has no enough resources
- block_
if_ boolsni_ mismatch - whether to block a session when certificate's subject name or SAN doesn't match SNI
- block_
timeout_ boolcert - Block sessions if certificate status cannot be retrieved within timeout
- block_
tls13_ booldowngrade_ no_ resource - whether to downgrade from tls1.3 if device has not enough resources
- block_
unknown_ boolcert - Block sessions if certificate status is unknown
- block_
unsupported_ boolcipher - Block sessions with unsupported cipher suites
- block_
unsupported_ boolversion - Block sessions with unsupported protocol versions
- block_
untrusted_ boolissuer - Block sessions with untrusted certificate issuers
- restrict_
cert_ boolexts - Restrict certificate extensions
- strip_
alpn bool - Strip ALPN extension from ClientHello
- auto
Include BooleanAltname - whether to automatically append SAN to impersonating certificate if server certificate is missing SAN
- block
Client BooleanCert - Block sessions with client certificate
- block
Expired BooleanCertificate - Block sessions with expired certificates
- Boolean
- whether to block sessions if HSM is unavailable
- block
If BooleanNo Resource - whether to block sessions if device has no enough resources
- block
If BooleanSni Mismatch - whether to block a session when certificate's subject name or SAN doesn't match SNI
- block
Timeout BooleanCert - Block sessions if certificate status cannot be retrieved within timeout
- block
Tls13Downgrade BooleanNo Resource - whether to downgrade from tls1.3 if device has not enough resources
- block
Unknown BooleanCert - Block sessions if certificate status is unknown
- block
Unsupported BooleanCipher - Block sessions with unsupported cipher suites
- block
Unsupported BooleanVersion - Block sessions with unsupported protocol versions
- block
Untrusted BooleanIssuer - Block sessions with untrusted certificate issuers
- restrict
Cert BooleanExts - Restrict certificate extensions
- strip
Alpn Boolean - Strip ALPN extension from ClientHello
- auto
Include booleanAltname - whether to automatically append SAN to impersonating certificate if server certificate is missing SAN
- block
Client booleanCert - Block sessions with client certificate
- block
Expired booleanCertificate - Block sessions with expired certificates
- boolean
- whether to block sessions if HSM is unavailable
- block
If booleanNo Resource - whether to block sessions if device has no enough resources
- block
If booleanSni Mismatch - whether to block a session when certificate's subject name or SAN doesn't match SNI
- block
Timeout booleanCert - Block sessions if certificate status cannot be retrieved within timeout
- block
Tls13Downgrade booleanNo Resource - whether to downgrade from tls1.3 if device has not enough resources
- block
Unknown booleanCert - Block sessions if certificate status is unknown
- block
Unsupported booleanCipher - Block sessions with unsupported cipher suites
- block
Unsupported booleanVersion - Block sessions with unsupported protocol versions
- block
Untrusted booleanIssuer - Block sessions with untrusted certificate issuers
- restrict
Cert booleanExts - Restrict certificate extensions
- strip
Alpn boolean - Strip ALPN extension from ClientHello
- auto_
include_ boolaltname - whether to automatically append SAN to impersonating certificate if server certificate is missing SAN
- block_
client_ boolcert - Block sessions with client certificate
- block_
expired_ boolcertificate - Block sessions with expired certificates
- bool
- whether to block sessions if HSM is unavailable
- block_
if_ boolno_ resource - whether to block sessions if device has no enough resources
- block_
if_ boolsni_ mismatch - whether to block a session when certificate's subject name or SAN doesn't match SNI
- block_
timeout_ boolcert - Block sessions if certificate status cannot be retrieved within timeout
- block_
tls13_ booldowngrade_ no_ resource - whether to downgrade from tls1.3 if device has not enough resources
- block_
unknown_ boolcert - Block sessions if certificate status is unknown
- block_
unsupported_ boolcipher - Block sessions with unsupported cipher suites
- block_
unsupported_ boolversion - Block sessions with unsupported protocol versions
- block_
untrusted_ boolissuer - Block sessions with untrusted certificate issuers
- restrict_
cert_ boolexts - Restrict certificate extensions
- strip_
alpn bool - Strip ALPN extension from ClientHello
- auto
Include BooleanAltname - whether to automatically append SAN to impersonating certificate if server certificate is missing SAN
- block
Client BooleanCert - Block sessions with client certificate
- block
Expired BooleanCertificate - Block sessions with expired certificates
- Boolean
- whether to block sessions if HSM is unavailable
- block
If BooleanNo Resource - whether to block sessions if device has no enough resources
- block
If BooleanSni Mismatch - whether to block a session when certificate's subject name or SAN doesn't match SNI
- block
Timeout BooleanCert - Block sessions if certificate status cannot be retrieved within timeout
- block
Tls13Downgrade BooleanNo Resource - whether to downgrade from tls1.3 if device has not enough resources
- block
Unknown BooleanCert - Block sessions if certificate status is unknown
- block
Unsupported BooleanCipher - Block sessions with unsupported cipher suites
- block
Unsupported BooleanVersion - Block sessions with unsupported protocol versions
- block
Untrusted BooleanIssuer - Block sessions with untrusted certificate issuers
- restrict
Cert BooleanExts - Restrict certificate extensions
- strip
Alpn Boolean - Strip ALPN extension from ClientHello
GetDecryptionProfileSslInboundProxy
- bool
- Block sessions when HSM is unavailable
- Block
If boolNo Resource - Block sessions when decryption resources are not available
- Block
Tls13Downgrade boolNo Resource - Block TLS 1.3 downgrade when no resources are available
- Block
Unsupported boolCipher - Block sessions with unsupported cipher suites
- Block
Unsupported boolVersion - Block sessions with unsupported protocol versions
- bool
- Block sessions when HSM is unavailable
- Block
If boolNo Resource - Block sessions when decryption resources are not available
- Block
Tls13Downgrade boolNo Resource - Block TLS 1.3 downgrade when no resources are available
- Block
Unsupported boolCipher - Block sessions with unsupported cipher suites
- Block
Unsupported boolVersion - Block sessions with unsupported protocol versions
- bool
- Block sessions when HSM is unavailable
- block_
if_ boolno_ resource - Block sessions when decryption resources are not available
- block_
tls13_ booldowngrade_ no_ resource - Block TLS 1.3 downgrade when no resources are available
- block_
unsupported_ boolcipher - Block sessions with unsupported cipher suites
- block_
unsupported_ boolversion - Block sessions with unsupported protocol versions
- Boolean
- Block sessions when HSM is unavailable
- block
If BooleanNo Resource - Block sessions when decryption resources are not available
- block
Tls13Downgrade BooleanNo Resource - Block TLS 1.3 downgrade when no resources are available
- block
Unsupported BooleanCipher - Block sessions with unsupported cipher suites
- block
Unsupported BooleanVersion - Block sessions with unsupported protocol versions
- boolean
- Block sessions when HSM is unavailable
- block
If booleanNo Resource - Block sessions when decryption resources are not available
- block
Tls13Downgrade booleanNo Resource - Block TLS 1.3 downgrade when no resources are available
- block
Unsupported booleanCipher - Block sessions with unsupported cipher suites
- block
Unsupported booleanVersion - Block sessions with unsupported protocol versions
- bool
- Block sessions when HSM is unavailable
- block_
if_ boolno_ resource - Block sessions when decryption resources are not available
- block_
tls13_ booldowngrade_ no_ resource - Block TLS 1.3 downgrade when no resources are available
- block_
unsupported_ boolcipher - Block sessions with unsupported cipher suites
- block_
unsupported_ boolversion - Block sessions with unsupported protocol versions
- Boolean
- Block sessions when HSM is unavailable
- block
If BooleanNo Resource - Block sessions when decryption resources are not available
- block
Tls13Downgrade BooleanNo Resource - Block TLS 1.3 downgrade when no resources are available
- block
Unsupported BooleanCipher - Block sessions with unsupported cipher suites
- block
Unsupported BooleanVersion - Block sessions with unsupported protocol versions
GetDecryptionProfileSslNoProxy
- Block
Expired boolCertificate - Block sessions with expired certificates
- Block
Untrusted boolIssuer - Block sessions with untrusted certificate issuers
- Block
Expired boolCertificate - Block sessions with expired certificates
- Block
Untrusted boolIssuer - Block sessions with untrusted certificate issuers
- block_
expired_ boolcertificate - Block sessions with expired certificates
- block_
untrusted_ boolissuer - Block sessions with untrusted certificate issuers
- block
Expired BooleanCertificate - Block sessions with expired certificates
- block
Untrusted BooleanIssuer - Block sessions with untrusted certificate issuers
- block
Expired booleanCertificate - Block sessions with expired certificates
- block
Untrusted booleanIssuer - Block sessions with untrusted certificate issuers
- block_
expired_ boolcertificate - Block sessions with expired certificates
- block_
untrusted_ boolissuer - Block sessions with untrusted certificate issuers
- block
Expired BooleanCertificate - Block sessions with expired certificates
- block
Untrusted BooleanIssuer - Block sessions with untrusted certificate issuers
GetDecryptionProfileSslProtocolSettings
- Auth
Algo boolMd5 - Allow MD5 authentication algorithm
- Auth
Algo boolSha1 - Allow SHA1 authentication algorithm
- Auth
Algo boolSha256 - Allow SHA256 authentication algorithm
- Auth
Algo boolSha384 - Allow SHA384 authentication algorithm
- Enc
Algo3des bool - Allow 3DES encryption algorithm
- Enc
Algo boolAes128Cbc - Allow AES-128-CBC encryption algorithm
- Enc
Algo boolAes128Gcm - Allow AES-128-GCM encryption algorithm
- Enc
Algo boolAes256Cbc - Allow AES-256-CBC encryption algorithm
- Enc
Algo boolAes256Gcm - Allow AES-256-GCM encryption algorithm
- Enc
Algo boolChacha20Poly1305 - Allow algorithm chacha20-poly1305
- Enc
Algo boolRc4 - Allow RC4 encryption algorithm
- Keyxchg
Algo boolDhe - Allow DHE key exchange algorithm
- Keyxchg
Algo boolEcdhe - Allow ECDHE key exchange algorithm
- Keyxchg
Algo boolRsa - Allow RSA key exchange algorithm
- Max
Version string - Maximum SSL/TLS protocol version
- Min
Version string - Minimum SSL/TLS protocol version
- Auth
Algo boolMd5 - Allow MD5 authentication algorithm
- Auth
Algo boolSha1 - Allow SHA1 authentication algorithm
- Auth
Algo boolSha256 - Allow SHA256 authentication algorithm
- Auth
Algo boolSha384 - Allow SHA384 authentication algorithm
- Enc
Algo3des bool - Allow 3DES encryption algorithm
- Enc
Algo boolAes128Cbc - Allow AES-128-CBC encryption algorithm
- Enc
Algo boolAes128Gcm - Allow AES-128-GCM encryption algorithm
- Enc
Algo boolAes256Cbc - Allow AES-256-CBC encryption algorithm
- Enc
Algo boolAes256Gcm - Allow AES-256-GCM encryption algorithm
- Enc
Algo boolChacha20Poly1305 - Allow algorithm chacha20-poly1305
- Enc
Algo boolRc4 - Allow RC4 encryption algorithm
- Keyxchg
Algo boolDhe - Allow DHE key exchange algorithm
- Keyxchg
Algo boolEcdhe - Allow ECDHE key exchange algorithm
- Keyxchg
Algo boolRsa - Allow RSA key exchange algorithm
- Max
Version string - Maximum SSL/TLS protocol version
- Min
Version string - Minimum SSL/TLS protocol version
- auth_
algo_ boolmd5 - Allow MD5 authentication algorithm
- auth_
algo_ boolsha1 - Allow SHA1 authentication algorithm
- auth_
algo_ boolsha256 - Allow SHA256 authentication algorithm
- auth_
algo_ boolsha384 - Allow SHA384 authentication algorithm
- enc_
algo3des bool - Allow 3DES encryption algorithm
- enc_
algo_ boolaes128_ cbc - Allow AES-128-CBC encryption algorithm
- enc_
algo_ boolaes128_ gcm - Allow AES-128-GCM encryption algorithm
- enc_
algo_ boolaes256_ cbc - Allow AES-256-CBC encryption algorithm
- enc_
algo_ boolaes256_ gcm - Allow AES-256-GCM encryption algorithm
- enc_
algo_ boolchacha20_ poly1305 - Allow algorithm chacha20-poly1305
- enc_
algo_ boolrc4 - Allow RC4 encryption algorithm
- keyxchg_
algo_ booldhe - Allow DHE key exchange algorithm
- keyxchg_
algo_ boolecdhe - Allow ECDHE key exchange algorithm
- keyxchg_
algo_ boolrsa - Allow RSA key exchange algorithm
- max_
version string - Maximum SSL/TLS protocol version
- min_
version string - Minimum SSL/TLS protocol version
- auth
Algo BooleanMd5 - Allow MD5 authentication algorithm
- auth
Algo BooleanSha1 - Allow SHA1 authentication algorithm
- auth
Algo BooleanSha256 - Allow SHA256 authentication algorithm
- auth
Algo BooleanSha384 - Allow SHA384 authentication algorithm
- enc
Algo3des Boolean - Allow 3DES encryption algorithm
- enc
Algo BooleanAes128Cbc - Allow AES-128-CBC encryption algorithm
- enc
Algo BooleanAes128Gcm - Allow AES-128-GCM encryption algorithm
- enc
Algo BooleanAes256Cbc - Allow AES-256-CBC encryption algorithm
- enc
Algo BooleanAes256Gcm - Allow AES-256-GCM encryption algorithm
- enc
Algo BooleanChacha20Poly1305 - Allow algorithm chacha20-poly1305
- enc
Algo BooleanRc4 - Allow RC4 encryption algorithm
- keyxchg
Algo BooleanDhe - Allow DHE key exchange algorithm
- keyxchg
Algo BooleanEcdhe - Allow ECDHE key exchange algorithm
- keyxchg
Algo BooleanRsa - Allow RSA key exchange algorithm
- max
Version String - Maximum SSL/TLS protocol version
- min
Version String - Minimum SSL/TLS protocol version
- auth
Algo booleanMd5 - Allow MD5 authentication algorithm
- auth
Algo booleanSha1 - Allow SHA1 authentication algorithm
- auth
Algo booleanSha256 - Allow SHA256 authentication algorithm
- auth
Algo booleanSha384 - Allow SHA384 authentication algorithm
- enc
Algo3des boolean - Allow 3DES encryption algorithm
- enc
Algo booleanAes128Cbc - Allow AES-128-CBC encryption algorithm
- enc
Algo booleanAes128Gcm - Allow AES-128-GCM encryption algorithm
- enc
Algo booleanAes256Cbc - Allow AES-256-CBC encryption algorithm
- enc
Algo booleanAes256Gcm - Allow AES-256-GCM encryption algorithm
- enc
Algo booleanChacha20Poly1305 - Allow algorithm chacha20-poly1305
- enc
Algo booleanRc4 - Allow RC4 encryption algorithm
- keyxchg
Algo booleanDhe - Allow DHE key exchange algorithm
- keyxchg
Algo booleanEcdhe - Allow ECDHE key exchange algorithm
- keyxchg
Algo booleanRsa - Allow RSA key exchange algorithm
- max
Version string - Maximum SSL/TLS protocol version
- min
Version string - Minimum SSL/TLS protocol version
- auth_
algo_ boolmd5 - Allow MD5 authentication algorithm
- auth_
algo_ boolsha1 - Allow SHA1 authentication algorithm
- auth_
algo_ boolsha256 - Allow SHA256 authentication algorithm
- auth_
algo_ boolsha384 - Allow SHA384 authentication algorithm
- enc_
algo3des bool - Allow 3DES encryption algorithm
- enc_
algo_ boolaes128_ cbc - Allow AES-128-CBC encryption algorithm
- enc_
algo_ boolaes128_ gcm - Allow AES-128-GCM encryption algorithm
- enc_
algo_ boolaes256_ cbc - Allow AES-256-CBC encryption algorithm
- enc_
algo_ boolaes256_ gcm - Allow AES-256-GCM encryption algorithm
- enc_
algo_ boolchacha20_ poly1305 - Allow algorithm chacha20-poly1305
- enc_
algo_ boolrc4 - Allow RC4 encryption algorithm
- keyxchg_
algo_ booldhe - Allow DHE key exchange algorithm
- keyxchg_
algo_ boolecdhe - Allow ECDHE key exchange algorithm
- keyxchg_
algo_ boolrsa - Allow RSA key exchange algorithm
- max_
version str - Maximum SSL/TLS protocol version
- min_
version str - Minimum SSL/TLS protocol version
- auth
Algo BooleanMd5 - Allow MD5 authentication algorithm
- auth
Algo BooleanSha1 - Allow SHA1 authentication algorithm
- auth
Algo BooleanSha256 - Allow SHA256 authentication algorithm
- auth
Algo BooleanSha384 - Allow SHA384 authentication algorithm
- enc
Algo3des Boolean - Allow 3DES encryption algorithm
- enc
Algo BooleanAes128Cbc - Allow AES-128-CBC encryption algorithm
- enc
Algo BooleanAes128Gcm - Allow AES-128-GCM encryption algorithm
- enc
Algo BooleanAes256Cbc - Allow AES-256-CBC encryption algorithm
- enc
Algo BooleanAes256Gcm - Allow AES-256-GCM encryption algorithm
- enc
Algo BooleanChacha20Poly1305 - Allow algorithm chacha20-poly1305
- enc
Algo BooleanRc4 - Allow RC4 encryption algorithm
- keyxchg
Algo BooleanDhe - Allow DHE key exchange algorithm
- keyxchg
Algo BooleanEcdhe - Allow ECDHE key exchange algorithm
- keyxchg
Algo BooleanRsa - Allow RSA key exchange algorithm
- max
Version String - Maximum SSL/TLS protocol version
- min
Version String - Minimum SSL/TLS protocol version
Package Details
- Repository
- panos paloaltonetworks/terraform-provider-panos
- License
- Notes
- This Pulumi package is based on the
panosTerraform Provider.
Viewing docs for panos 2.0.12
published on Wednesday, Jun 17, 2026 by paloaltonetworks
published on Wednesday, Jun 17, 2026 by paloaltonetworks