<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Inspection and SSL Labs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544973#M111487</link>
    <description>&lt;P&gt;Is this related to decrypting user traffic to website hosted somewhere in internet or you host web server and trying to set up ssl decryption for traffic from internet towards your web server?&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jun 2023 17:32:38 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-06-06T17:32:38Z</dc:date>
    <item>
      <title>SSL Inspection and SSL Labs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544959#M111483</link>
      <description>&lt;P&gt;Outside of minimum and maximum supported tls versions and ciphers what are some things to look for on SSL Labs that would be breaking decryption. In the Palo decryption logs if it shows error "Early close notify" what would be something to look for as the root cause?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 15:36:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544959#M111483</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2023-06-06T15:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inspection and SSL Labs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544964#M111485</link>
      <description>&lt;P&gt;Are you having issues with ssl decryption if users access the site?&lt;/P&gt;
&lt;P&gt;SSL Labs by design will try different cipher settings and tests site security posture so seeing logs about failed connections in firewall logs is expected when those tests are performed.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 16:12:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544964#M111485</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-06-06T16:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inspection and SSL Labs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544967#M111486</link>
      <description>&lt;P&gt;Yeah site is breaking for users when ssl inspection is applied, I can bypass that url from decryption and it works fine then. Saw the decryption logs showed "early close notify" then ran an SSL Labs check after the fact to see if anything stuck out.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 16:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544967#M111486</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2023-06-06T16:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inspection and SSL Labs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544973#M111487</link>
      <description>&lt;P&gt;Is this related to decrypting user traffic to website hosted somewhere in internet or you host web server and trying to set up ssl decryption for traffic from internet towards your web server?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 17:32:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544973#M111487</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-06-06T17:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inspection and SSL Labs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544978#M111489</link>
      <description>&lt;P&gt;Forward proxy for internet traffic. Just curious what "early close notify" indicates or if there is anything to look for on the SSL Labs report that would indicate why its breaking.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 18:01:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544978#M111489</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2023-06-06T18:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inspection and SSL Labs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544989#M111491</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I agree with you.&amp;nbsp; It would be nice if PANW had an index of decryption errors.&amp;nbsp; I found this -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/decryption-log-errors-and-error-indexes" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/decryption-log-errors-and-error-indexes&lt;/A&gt; but an index of every error and cause would be nice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 20:04:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/544989#M111491</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-06T20:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inspection and SSL Labs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/545527#M111552</link>
      <description>&lt;P&gt;Claw4609, I have recently just started to see a ton of early close notify Protocol errors on our PA's for and it seems to have just started. Some of the sites are well known sites with a fully trusted chains such as youtube.com and connectivitycheck.gstatic.com. &lt;BR /&gt;Is that what you are seeing?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 21:50:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/545527#M111552</guid>
      <dc:creator>Chris_S</dc:creator>
      <dc:date>2023-06-09T21:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Inspection and SSL Labs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/545566#M111554</link>
      <description>&lt;P&gt;Not necessarily on those sites specifically but we are seeing it on some notable sites.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2023 22:11:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inspection-and-ssl-labs/m-p/545566#M111554</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2023-06-10T22:11:36Z</dc:date>
    </item>
  </channel>
</rss>

