<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What SSL/TLS versions are allowed for WEBUI in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13927#M10220</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a small test with IE to open WEBUI for PAN-FW management interface. It is working only with SSL 3.0 and TLS 1.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Jan 2014 20:24:23 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-01-15T20:24:23Z</dc:date>
    <item>
      <title>What SSL/TLS versions are allowed for WEBUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13923#M10216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I'm trying to verify which SSL/TLS versions and Ciphers the PANs accept for WEBUI connections.&amp;nbsp; Specifically I am trying to verify that it does not accept connections using weaker Protocols or Cipers and if it is configurable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note that this is for Management connections to the PANs only, not user traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 15:27:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13923#M10216</guid>
      <dc:creator>TSPphooper</dc:creator>
      <dc:date>2014-01-14T15:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: What SSL/TLS versions are allowed for WEBUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13924#M10217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;To log into the firewall, the browser must be TLS 1.0 compatible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H5 style="font-family: 'PT Sans', 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Ciphers&lt;/SPAN&gt; suits for Admin Sessions (web interface):&lt;/H5&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;DHE-RSA-AES256-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;RSA-AES256-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;DHE-RSA-CAMELLIA256-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;RSA-CAMELLIA256-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;EDH-RSA-3DES-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;RSA-3DES-SHA (aka RSA-DES-CBC3-SHA aka DES-CBC3-SHA)&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;DHE-RSA-AES128-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;RSA-AES128-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;DHE-RSA-SEED-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;RSA-SEED-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;DHE-RSA-CAMELLIA128-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;CAMELLIA128-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;RSA-RC4-SHA&lt;/P&gt;&lt;P style="margin-bottom: 10px; font-size: 12px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;RSA-RC4-MD5&lt;/P&gt;&lt;P&gt;For data-plane traffic, The SSL versions supported by PAN-OS are: SSLv3, TLS1.0, and TLS1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it will help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 15:53:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13924#M10217</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-14T15:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: What SSL/TLS versions are allowed for WEBUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13925#M10218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for the Reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Is TLS 1.0 the only protocol that can be used for the Management Interface?&amp;nbsp; Older protocols such as SSLv2 will be denied and are not supported?&amp;nbsp; I suspect the answer is yes but need to verify.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2014 16:56:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13925#M10218</guid>
      <dc:creator>TSPphooper</dc:creator>
      <dc:date>2014-01-15T16:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: What SSL/TLS versions are allowed for WEBUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13926#M10219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2014 18:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13926#M10219</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-15T18:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: What SSL/TLS versions are allowed for WEBUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13927#M10220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a small test with IE to open WEBUI for PAN-FW management interface. It is working only with SSL 3.0 and TLS 1.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2014 20:24:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13927#M10220</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-15T20:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: What SSL/TLS versions are allowed for WEBUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13928#M10221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the release notes for PANOS 6.0 most devices will now support TLS 1.2 for dataplane ssl/tls decryption.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jan 2014 08:34:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13928#M10221</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2014-01-21T08:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: What SSL/TLS versions are allowed for WEBUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13929#M10222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mikand, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct, The new PAN OS 6.0 is having capability to decrypt TLS 1.2. Although&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; PANOS 5.0, if we detect a TLS1.1 or TLS1.2 session, we first try to downgrade it to TLS1.0 and decrypt. If that fails, we won't decrypt the session and either drop the session or allow it encrypted based upon your policy settings.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jan 2014 15:32:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13929#M10222</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-21T15:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: What SSL/TLS versions are allowed for WEBUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13930#M10223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to block sslv3 access to management interface of the firewall and allow only TLS1.0 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2014 20:01:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13930#M10223</guid>
      <dc:creator>mbavishi</dc:creator>
      <dc:date>2014-10-20T20:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: What SSL/TLS versions are allowed for WEBUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13931#M10224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mbavishi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latest content has fix for vulnerability related sslv3, if management traffic is traversing through the Dataports than it can blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, there is no way to block it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2014 22:10:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13931#M10224</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-20T22:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: What SSL/TLS versions are allowed for WEBUI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13932#M10225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mbavishi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer following thread for more detail.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/45776"&gt;Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2014 22:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ssl-tls-versions-are-allowed-for-webui/m-p/13932#M10225</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-20T22:29:23Z</dc:date>
    </item>
  </channel>
</rss>

