<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption+ALPN not stripped: yandex.com not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/456795#M101762</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36075"&gt;@ShaiW&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems you have figure it out by yourself.&lt;/P&gt;
&lt;P&gt;Strip-ALPN will basically dowgrade HTTP/2 to HTTP/1.1 and if I understand you correctly your decryption profile is configured with max version TLS 1.2. It sounds like removing the "strip ALPN" will leave HTTP/2, but it is failing because your decryption does not support TLS 1.3. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is better to configure your profile to use max version with "max" and set the min version to specific version&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_1-1641333464832.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38517i3C7905F24A5C5BCC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_1-1641333464832.png" alt="Astardzhiev_1-1641333464832.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This will make sure that when new TLS version is supported by the PanOS, you don't have to update your configuration (like in this case)&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jan 2022 21:57:53 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2022-01-04T21:57:53Z</dc:date>
    <item>
      <title>SSL Decryption+ALPN not stripped: yandex.com not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/456631#M101749</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a customer that wrote to me yesterday that if they remove the checkbox for Strip ALPN while having SSL decryption enabled, a few web sites such as yandex.com stop working.&lt;/P&gt;&lt;P&gt;I was able to reproduce this with my PA-3220 and PANOS 9.1 and also on my VM with PANOS 10, the result is ERR_HTTP2_PROTOCOL_ERROR in Edge browser. There do not appear to be any decrypt-error messages and in the traffic log it appears like a normal decrypted session.&lt;/P&gt;&lt;P&gt;I dug through the PCAP file, can see the chosen cipher and verified that it is indeed listed as available on firewall. Also counters do not show drops.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have an idea what could cause this? Right now the customer has a decryption policy with Strip-ALPN enabled for these few sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Shai&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 06:56:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/456631#M101749</guid>
      <dc:creator>ShaiW</dc:creator>
      <dc:date>2022-01-04T06:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption+ALPN not stripped: yandex.com not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/456704#M101755</link>
      <description>&lt;P&gt;EDIT: This web site starts working if I change max version to TLS 1.3 (under decryption profile) and stops working when I set it at TLS 1.2. No other changes are made.&lt;/P&gt;&lt;P&gt;This feels like a specific web-site issue more than a firewall one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 15:04:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/456704#M101755</guid>
      <dc:creator>ShaiW</dc:creator>
      <dc:date>2022-01-04T15:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption+ALPN not stripped: yandex.com not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/456795#M101762</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36075"&gt;@ShaiW&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems you have figure it out by yourself.&lt;/P&gt;
&lt;P&gt;Strip-ALPN will basically dowgrade HTTP/2 to HTTP/1.1 and if I understand you correctly your decryption profile is configured with max version TLS 1.2. It sounds like removing the "strip ALPN" will leave HTTP/2, but it is failing because your decryption does not support TLS 1.3. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is better to configure your profile to use max version with "max" and set the min version to specific version&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_1-1641333464832.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38517i3C7905F24A5C5BCC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_1-1641333464832.png" alt="Astardzhiev_1-1641333464832.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This will make sure that when new TLS version is supported by the PanOS, you don't have to update your configuration (like in this case)&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 21:57:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/456795#M101762</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-01-04T21:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption+ALPN not stripped: yandex.com not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/456897#M101767</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The customer is still on PAN-OS 9 which does not support TLS 1.3 and all other web sites work fine. Its just yandex.com that does not.&lt;/P&gt;&lt;P&gt;I am pretty sure it is not firewall related, more like a web-site issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shai&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 07:36:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/456897#M101767</guid>
      <dc:creator>ShaiW</dc:creator>
      <dc:date>2022-01-05T07:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption+ALPN not stripped: yandex.com not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/511827#M106377</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Use with caution- at 3430 pair the workaround Min=TLS1.2 and Max=Max crashed firewall. Used PanOS 10.2.1&lt;/P&gt;
&lt;P&gt;For the issue with&amp;nbsp;&lt;SPAN&gt;ERR_HTTP2_PROTOCOL_ERROR the config change fixed it but just for a minute between commiting the change and till the FW crashed into maint mode.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 07:23:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-alpn-not-stripped-yandex-com-not-working/m-p/511827#M106377</guid>
      <dc:creator>Trustnet-ET</dc:creator>
      <dc:date>2022-08-15T07:23:07Z</dc:date>
    </item>
  </channel>
</rss>

