<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: session_end_reason eq decrypt-error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/459894#M102016</link>
    <description>&lt;P&gt;Did you ever get this fixed?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jan 2022 18:31:36 GMT</pubDate>
    <dc:creator>tjjohnso</dc:creator>
    <dc:date>2022-01-20T18:31:36Z</dc:date>
    <item>
      <title>session_end_reason eq decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/158881#M52032</link>
      <description>&lt;P&gt;I have a high number of sessions, for various webservers and clients, being closed due to decrypt-error. I've attempted to follow the tips from this document, but I'm still not clear on root cause:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/PAN-OS-7-1-New-session-end-reasons/ta-p/73289" target="_blank" rel="nofollow"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/PAN-OS-7-1-New-session-end-reasons/ta-p/73289&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need help identifying why sessions are ending with message "decrypt-error"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are a few of the messages I'm seeing the debug logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2017-05-30 13:43:19.466 -0400 Error: pan_ssl3_client_process_handshake(pan_ssl_client.c:871): pan_ssl3_client_get_server_hello() failed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2017-05-30 13:43:19.466 -0400 Error: pan_ssl_proxy_handle_rt_hs(pan_ssl_proxy.c:236): pan_ssl3_process_handshake_message() failed -6&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2017-05-30 13:43:19.466 -0400 Error: pan_ssl_proxy_parse_data(pan_ssl_proxy.c:550): pan_ssl_parse_record() failed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2017-05-30 13:43:19.467 -0400 Warning: pan_aho_fpga_lookup(pan_aho.c:2438): too many matches in buffer&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2017-05-30 13:43:19.467 -0400 Warning: pan_aho_fpga_lookup(pan_aho.c:2438): too many matches in buffer&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2017-05-30 13:43:19.462 -0400 Warning: pan_ssl3_server_get_client_hello(pan_ssl_server.c:1127): extra message at the end 2&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 14:26:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/158881#M52032</guid>
      <dc:creator>AmyTyler</dc:creator>
      <dc:date>2017-06-01T14:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: session_end_reason eq decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/158912#M52049</link>
      <description>What is "a high number" meaning? On which hardware do you have these problems? And because of the link you provided is it correct that you run 7.1.x?&lt;BR /&gt;Do you have an example of a decrypt-error-website and may be also analyzed this server for example on ssllabs.com or htbridge.com or manually with openssl/sslyze?&lt;BR /&gt;But if you say a high number I assume at least some websites work, right? So it isn't a general decryption issue on your firewall.</description>
      <pubDate>Thu, 01 Jun 2017 18:03:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/158912#M52049</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-01T18:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: session_end_reason eq decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/159019#M52059</link>
      <description>&lt;P&gt;Hi - by high number I mean it is happening frequently, but not all the time. So, it's not a general decryption issue but I'm having a hard time isolating it to any specific client or webserver behind the PA. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I observed traffic logs for 1 client connecting to the same web server behind the PA 5020 and not all sessions end with the decrypt-error. Some end normally.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hardware is a 5020 running 7.1.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was thinking that if I have more info on the errors&amp;nbsp;in the debug log, that'll help me narrow my search.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 20:11:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/159019#M52059</guid>
      <dc:creator>AmyTyler</dc:creator>
      <dc:date>2017-06-01T20:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: session_end_reason eq decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/159043#M52061</link>
      <description>&lt;P&gt;Hello Amy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming this is for SSL forward proxy and not for inbound inspection.&lt;/P&gt;&lt;P&gt;Please collect these informations.&lt;/P&gt;&lt;P&gt;&amp;gt; show session all filter ssl-decrypt yes count yes&lt;BR /&gt;&amp;gt; show session all filter state discard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you know any specific machine (source IP from the logs) please collect below mentioned information for get the actual reason for failure.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. Enable packet-diag (ctd, ssl, proxy).&lt;BR /&gt;2. Enable packet capture on firewall (recv, firewall, drop) with a specific filter ( i.e source IP and destination set to 0.0.0.0).&lt;BR /&gt;3. take global counter o/p 5 times with a 5 seconds interval.&lt;BR /&gt;&amp;gt; show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;You may also check these 2 options.&lt;/P&gt;&lt;P&gt;a. Double check the min TLS version on the firewall&lt;BR /&gt;b. Disable Extended Master Secret on client&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 21:32:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/159043#M52061</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2017-06-01T21:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: session_end_reason eq decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/159491#M52127</link>
      <description>&lt;P&gt;Hi Hulk - I should've specified this is for inbounc encryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the best way to check for the min tls version supported?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 17:22:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/159491#M52127</guid>
      <dc:creator>AmyTyler</dc:creator>
      <dc:date>2017-06-05T17:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: session_end_reason eq decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/159508#M52129</link>
      <description>The min TLS version is the one you configured in the decryption profile that you applied to the decryption rule. If you did not specify a profile the min version is sslv3</description>
      <pubDate>Mon, 05 Jun 2017 18:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/159508#M52129</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-05T18:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: session_end_reason eq decrypt-error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/459894#M102016</link>
      <description>&lt;P&gt;Did you ever get this fixed?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 18:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-end-reason-eq-decrypt-error/m-p/459894#M102016</guid>
      <dc:creator>tjjohnso</dc:creator>
      <dc:date>2022-01-20T18:31:36Z</dc:date>
    </item>
  </channel>
</rss>

