<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Audit Global protect server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527254#M108938</link>
    <description>&lt;P&gt;I had already restored from backup the previous config so I just ran the commands and attempted commit again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A new profile was not created according to the GUI. I looked in all the associated templates and template stacks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am now restoring back to original.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jan 2023 19:42:25 GMT</pubDate>
    <dc:creator>DavidJohnson</dc:creator>
    <dc:date>2023-01-16T19:42:25Z</dc:date>
    <item>
      <title>Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/340873#M85526</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We launched a sslab test for a GlobalProtect Portal website. Our note is B. We would like to improve these two things but we dont know what it can be done in PA config. These are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="warningBox"&gt;There is no support for secure renegotiation. &amp;nbsp;&lt;A href="https://community.qualys.com/blogs/securitylabs/2010/10/06/disabling-ssl-renegotiation-is-a-crutch-not-a-fix" target="_blank"&gt;&lt;SPAN class="moreInfo"&gt;MORE&amp;nbsp;INFO&amp;nbsp;»&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;DIV class="warningBox"&gt;This server does not support Forward Secrecy with the reference browsers. Grade capped to B. &amp;nbsp;&lt;A href="https://blog.qualys.com/ssllabs/2018/02/02/forward-secrecy-authenticated-encryption-and-robot-grading-update" target="_blank"&gt;&lt;SPAN class="moreInfo"&gt;MORE&amp;nbsp;INFO&amp;nbsp;»&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;DIV class="warningBox"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="warningBox"&gt;&lt;SPAN class="moreInfo"&gt;What means "secure renegotiation"? how can solve this in PA?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="warningBox"&gt;&lt;SPAN class="moreInfo"&gt;what about Palo support froward secrecy? anything to do in Palo?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="warningBox"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 27 Jul 2020 15:32:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/340873#M85526</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-07-27T15:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/341723#M85716</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Forward secrecy actually is supported by paloalto. If you look at the details of the browser handshake list, you should see most of them use ciphersuites with forward secrecy. Only a few - which count as reference browser for Qualys SSLLabs - do not use forward secrecy ciphersuites.&lt;/P&gt;
&lt;P&gt;The point with the missing secure renegotiation is still true and unfortunately theres nothing you can do about that at the moment except wait until it is supportet (in PAN-OS 10 it is still not supported).&lt;/P&gt;
&lt;P&gt;An explanation of secure renegotiation you can find here:&amp;nbsp;&lt;A href="https://devcentral.f5.com/s/articles/ssl-legacy-renegotiation-vs-secure-renegotiation-explained-using-wireshark-34023" target="_blank"&gt;https://devcentral.f5.com/s/articles/ssl-legacy-renegotiation-vs-secure-renegotiation-explained-using-wireshark-34023&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2020 10:01:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/341723#M85716</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-01T10:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/347870#M86676</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can easily get A minus on SSLlabs and take out most of the forward secrecy.&lt;/P&gt;&lt;P&gt;I assume you have your&amp;nbsp;ssl-tls-service-profile set at minimum TLS 1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just run the following via the CLI:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;configure&lt;/LI&gt;&lt;LI&gt;set shared ssl-tls-service-profile yourprofile protocol-settings auth-algo-sha1 no&lt;/LI&gt;&lt;LI&gt;set shared ssl-tls-service-profile yourprofile protocol-settings enc-algo-3des no&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While you are at it also disable the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;set shared ssl-tls-service-profile yourprofile protocol-settings enc-algo-rc4 no&lt;/LI&gt;&lt;LI&gt;set shared ssl-tls-service-profile yourprofile protocol-settings keyxchg-algo-rsa no&lt;/LI&gt;&lt;LI&gt;commit&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Unfortunately it does not fix anything for&amp;nbsp;&lt;SPAN&gt;secure renegotiation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Raymond&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 10:51:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/347870#M86676</guid>
      <dc:creator>RaymondSchuiling</dc:creator>
      <dc:date>2020-09-09T10:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527237#M108933</link>
      <description>&lt;P&gt;Can this be done as a push from Panorama? I do not like the concept of doing a command line only change on an individual firewall which could easily be forgotten in the case of a disaster restore or upgrade situation.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 17:10:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527237#M108933</guid>
      <dc:creator>DavidJohnson</dc:creator>
      <dc:date>2023-01-16T17:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527245#M108935</link>
      <description>&lt;P&gt;You can run those commands in Panorama CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Instead of command:&lt;/P&gt;
&lt;P&gt;set shared ssl-tls-service-profile...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to use:&lt;/P&gt;
&lt;P&gt;set template &lt;EM&gt;TemplateName&lt;/EM&gt; config shared ssl-tls-service-profile...&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 18:15:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527245#M108935</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-16T18:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527246#M108936</link>
      <description>&lt;P&gt;I must be missing something...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I used the following commands (with the template name changed)&lt;/P&gt;
&lt;P&gt;set template HiddenTemplateName config shared ssl-tls-service-profile VPN-SSL protocol-settings auth-algo-sha1 no&lt;BR /&gt;set template HiddenTemplateName config shared ssl-tls-service-profile VPN-SSL protocol-settings enc-algo-3des no&lt;BR /&gt;set template HiddenTemplateName config shared ssl-tls-service-profile VPN-SSL protocol-settings enc-algo-rc4 no&lt;BR /&gt;set template HiddenTemplateName config shared ssl-tls-service-profile VPN-SSL protocol-settings keyxchg-algo-rsa no&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following commit failed with the result down below - what am I missing - all the profiles (there are three like this) have certificates already and in use?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Operation&lt;BR /&gt;Commit&lt;BR /&gt;Status&lt;BR /&gt;Completed&lt;BR /&gt;Result&lt;BR /&gt;Failed&lt;BR /&gt;Details&lt;BR /&gt;sd_wan plugin validation: Config valid&lt;BR /&gt;Validation Error:&lt;BR /&gt;devices -&amp;gt; localhost.localdomain -&amp;gt; template-stack -&amp;gt; HiddenStackName -&amp;gt; config -&amp;gt; shared -&amp;gt; ssl-tls-service-profile -&amp;gt; VPN-SSL is missing 'certificate'&lt;BR /&gt;devices -&amp;gt; localhost.localdomain -&amp;gt; template-stack -&amp;gt; HiddenStackName -&amp;gt; config -&amp;gt; shared -&amp;gt; ssl-tls-service-profile is invalid&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 18:53:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527246#M108936</guid>
      <dc:creator>DavidJohnson</dc:creator>
      <dc:date>2023-01-16T18:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527250#M108937</link>
      <description>&lt;P&gt;Go to "Device &amp;gt; Certificate management &amp;gt; SSL/TLS Service Profile"&lt;/P&gt;
&lt;P&gt;Did you use correct name for profile or did it create new one named "&lt;SPAN&gt;VPN-SSL" as a result of the command?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 19:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527250#M108937</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-16T19:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527254#M108938</link>
      <description>&lt;P&gt;I had already restored from backup the previous config so I just ran the commands and attempted commit again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A new profile was not created according to the GUI. I looked in all the associated templates and template stacks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am now restoring back to original.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 19:42:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527254#M108938</guid>
      <dc:creator>DavidJohnson</dc:creator>
      <dc:date>2023-01-16T19:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527255#M108939</link>
      <description>&lt;P&gt;Try to tab complete the command and use questionmark to get correct options.&lt;/P&gt;
&lt;P&gt;There must be typo in command somewhere.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 19:44:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527255#M108939</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-16T19:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527258#M108940</link>
      <description>&lt;P&gt;Just adding "" around the various template names did not change anything. The commands have always been accepted with and without the "".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using the ? as I worked through the first command I saw that certificate was an option. Adding that sub-command and then a ? again I was shown some certificates; however the one that is in use (from an external CA) was not in the list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like I will need to open a support ticket to get this sorted out.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 20:03:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527258#M108940</guid>
      <dc:creator>DavidJohnson</dc:creator>
      <dc:date>2023-01-16T20:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Global protect server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527264#M108941</link>
      <description>&lt;P&gt;No "" needed if template or profile names don't contain spaces.&lt;/P&gt;
&lt;P&gt;Command works well and commit worked after entering command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1673899937895.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47095i676139668A66302C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1673899937895.png" alt="Raido_Rattameister_0-1673899937895.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 20:12:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/audit-global-protect-server/m-p/527264#M108941</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-16T20:12:32Z</dc:date>
    </item>
  </channel>
</rss>

