<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: This server does not support Forward Secrecy with the reference browsers. Grade capped to B. in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/this-server-does-not-support-forward-secrecy-with-the-reference/m-p/595543#M5702</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for trying to help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The settings are as follows.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Oliver_Dalugodage_0-1724287239746.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61644iC87326CA319FFF20/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Oliver_Dalugodage_0-1724287239746.png" alt="Oliver_Dalugodage_0-1724287239746.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Cipher suits are as follows.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Oliver_Dalugodage_0-1724303176340.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61647iFB899FCC2764E548/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Oliver_Dalugodage_0-1724303176340.png" alt="Oliver_Dalugodage_0-1724303176340.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will check out your Youtube channel. Thank you for providing the info to it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Aug 2024 05:06:28 GMT</pubDate>
    <dc:creator>Oliver_Dalugodage</dc:creator>
    <dc:date>2024-08-22T05:06:28Z</dc:date>
    <item>
      <title>This server does not support Forward Secrecy with the reference browsers. Grade capped to B.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/this-server-does-not-support-forward-secrecy-with-the-reference/m-p/595431#M5694</link>
      <description>&lt;P&gt;Hi Champions,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have evaluated the IP address to&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;&amp;nbsp;the GlobalProtect gateway on the Palo Alto firewall via Qualys SSL Labs and got the following results.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Oliver_Dalugodage_0-1724221684555.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61621iB53F3D32C4138C22/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Oliver_Dalugodage_0-1724221684555.png" alt="Oliver_Dalugodage_0-1724221684555.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Object &amp;gt; Decryption &amp;gt; Decryption Profile&amp;nbsp;&lt;/STRONG&gt;is&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Oliver_Dalugodage_1-1724222240030.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61622i3457D821AE720F3C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Oliver_Dalugodage_1-1724222240030.png" alt="Oliver_Dalugodage_1-1724222240030.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to find out how to fix this issue of "&lt;SPAN&gt;This server does not support Forward Secrecy with the reference browsers. Grade capped to B."&lt;/SPAN&gt; to get the grade back to A.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Pan OS version is: 10.1.10-h2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please help me?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much for your attention and participation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 06:39:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/this-server-does-not-support-forward-secrecy-with-the-reference/m-p/595431#M5694</guid>
      <dc:creator>Oliver_Dalugodage</dc:creator>
      <dc:date>2024-08-21T06:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: This server does not support Forward Secrecy with the reference browsers. Grade capped to B.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/this-server-does-not-support-forward-secrecy-with-the-reference/m-p/595437#M5695</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1352883893"&gt;@Oliver_Dalugodage&lt;/a&gt;&amp;nbsp;Normally with DHE &amp;amp; ECDHE, it should be enabled by default on Palo Alto.&lt;/P&gt;
&lt;P&gt;Can you confirm what encryption and authentication algorithm are you using? It might be flagged due to weak algorithm being used.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SutareMayur_0-1724226240164.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61624iD37F1C0DE84FDCB6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SutareMayur_0-1724226240164.png" alt="SutareMayur_0-1724226240164.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 07:46:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/this-server-does-not-support-forward-secrecy-with-the-reference/m-p/595437#M5695</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2024-08-21T07:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: This server does not support Forward Secrecy with the reference browsers. Grade capped to B.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/this-server-does-not-support-forward-secrecy-with-the-reference/m-p/595543#M5702</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for trying to help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The settings are as follows.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Oliver_Dalugodage_0-1724287239746.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61644iC87326CA319FFF20/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Oliver_Dalugodage_0-1724287239746.png" alt="Oliver_Dalugodage_0-1724287239746.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Cipher suits are as follows.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Oliver_Dalugodage_0-1724303176340.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61647iFB899FCC2764E548/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Oliver_Dalugodage_0-1724303176340.png" alt="Oliver_Dalugodage_0-1724303176340.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will check out your Youtube channel. Thank you for providing the info to it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 05:06:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/this-server-does-not-support-forward-secrecy-with-the-reference/m-p/595543#M5702</guid>
      <dc:creator>Oliver_Dalugodage</dc:creator>
      <dc:date>2024-08-22T05:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: This server does not support Forward Secrecy with the reference browsers. Grade capped to B.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/this-server-does-not-support-forward-secrecy-with-the-reference/m-p/595742#M5716</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1352883893"&gt;@Oliver_Dalugodage&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should get a rid of CBC mode ciphers. Many Security organizations including Qualys where you are scanning your site, consider CBC ciphers to be weak. Due to this, there are few ciphers enabled which does not support PFS and so showing in your scanning report also. Kindly refer this &lt;A href="https://ciphersuite.info/cs/TLS_RSA_WITH_AES_256_CBC_SHA256/" target="_self"&gt;article.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 10:45:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/this-server-does-not-support-forward-secrecy-with-the-reference/m-p/595742#M5716</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2024-08-23T10:45:27Z</dc:date>
    </item>
  </channel>
</rss>

