<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: disable SSL V.3 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39075#M28644</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hardik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even in latest code, we have removed the SSL v3 from the code for management connection including GlobalProtect gateway, GlobalProtect portal, and Captive Portal. There is no such option or button to enable/disable SSL V3. Secondly, if you create a custom signature to block SSL V3 connection and the client keep initiating SSL V3 connection,&amp;nbsp; then you will not be able to establish a connection, which would be a major black-hole. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, custom signature would not be a recommended solution for production environment. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Jan 2015 19:01:36 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2015-01-28T19:01:36Z</dc:date>
    <item>
      <title>disable SSL V.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39071#M28640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;how we can disable SSL V.3&amp;nbsp; only for management console on PA firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;Satish&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jan 2015 17:29:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39071#M28640</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2015-01-28T17:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: disable SSL V.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39072#M28641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish, &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSL V3 option has been removed from the PAN OS 6.0.8 and 6.1.2 onward. Prior to these version, you do not have any option to disable SSL V3 on the firewall, rather, you may disable SSL-V3 on your web browser. Accordingly, the client will not send SSL-v3 during the handshake. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may go through the security advisory for more detail information: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-8360"&gt;SSL 3.0 MITM Attack (CVE-2014-3566) (PAN-SA-2014-0005) a.k.a. POODLE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below mentioned BUG has been fixed on PAN OS 6.0.8.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;71321—Removed support for SSL 3.0 from the GlobalProtect gateway, GlobalProtect portal, and Captive Portal due to CVE-2014-3566 (POODLE).&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; 71320—Removed support for SSL 3.0 from the web interface due to CVE-2014-3566 (POODLE).&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jan 2015 17:53:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39072#M28641</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-01-28T17:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: disable SSL V.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39073#M28642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One more related link: &lt;A href="https://securityadvisories.paloaltonetworks.com/" title="https://securityadvisories.paloaltonetworks.com/"&gt;Palo Alto Networks Product Vulnerability - Security Advisories&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look into the &lt;SPAN style="color: #333333; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; background-color: #d6e1e7;"&gt;SSL 3.0 MITM Attack (CVE-2014-3566)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jan 2015 17:57:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39073#M28642</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-01-28T17:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: disable SSL V.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39074#M28643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If firewall is not on the latest code, than you can not disable SSLv3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, there is one work around if management traffic is going through data plane. In that case through custom signature SSLv3 traffic can be blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jan 2015 18:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39074#M28643</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2015-01-28T18:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: disable SSL V.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39075#M28644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hardik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even in latest code, we have removed the SSL v3 from the code for management connection including GlobalProtect gateway, GlobalProtect portal, and Captive Portal. There is no such option or button to enable/disable SSL V3. Secondly, if you create a custom signature to block SSL V3 connection and the client keep initiating SSL V3 connection,&amp;nbsp; then you will not be able to establish a connection, which would be a major black-hole. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, custom signature would not be a recommended solution for production environment. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jan 2015 19:01:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39075#M28644</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-01-28T19:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: disable SSL V.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39076#M28645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When will 6.1.2 be released?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jan 2015 01:09:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39076#M28645</guid>
      <dc:creator>ASCIT</dc:creator>
      <dc:date>2015-01-29T01:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: disable SSL V.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39077#M28646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 11.6999998092651px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1245" data-externalid="" data-presence="null" data-userid="30544" data-username="ascit" href="https://live.paloaltonetworks.com/people/ascit" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;ascit&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PAN OS version 6.1.2 is expected to be released during the week of February 2, 2015. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jan 2015 02:48:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39077#M28646</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-01-29T02:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: disable SSL V.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39078#M28647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Hulk &amp;amp; &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Hardik for reply.&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Satish&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jan 2015 04:04:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-ssl-v-3/m-p/39078#M28647</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2015-01-29T04:04:51Z</dc:date>
    </item>
  </channel>
</rss>

