<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with ssh decryption after SSH server upgrade in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4663#M3432</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I;m not sure right now, what was previous version but was working correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Dec 2013 22:11:06 GMT</pubDate>
    <dc:creator>mariusz_sawczuk</dc:creator>
    <dc:date>2013-12-10T22:11:06Z</dc:date>
    <item>
      <title>Problem with ssh decryption after SSH server upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4661#M3430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After upgrade ssh server to OpenSSH_6.4p1-hpn14v2, OpenSSL 1.0.0j 10 May 2012 I can't connect to this server when using ssh decryption on Palo Alto.&lt;/P&gt;&lt;P&gt;Before ssh server upgrade, decryption was working correctly and I could connect and decrypt ssh traffic.&lt;/P&gt;&lt;P&gt;When I'm trying to connect from client PC I get response:'Server unexpectly closed network connection'.&lt;/P&gt;&lt;P&gt;I check that Palo Alto is sending this message to the client PC (as an SSH proxy) not the destination SSH server.&lt;/P&gt;&lt;P&gt;I also try to connect from the same client PC with SSH decryption turned off, and I could connect.&lt;/P&gt;&lt;P&gt;I'm using PA-3020 with 5.0.9 PAN-OS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 19:59:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4661#M3430</guid>
      <dc:creator>mariusz_sawczuk</dc:creator>
      <dc:date>2013-12-10T19:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssh decryption after SSH server upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4662#M3431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Was the server's version &amp;lt; 6.2 before the upgrade ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 20:18:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4662#M3431</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-12-10T20:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssh decryption after SSH server upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4663#M3432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I;m not sure right now, what was previous version but was working correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 22:11:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4663#M3432</guid>
      <dc:creator>mariusz_sawczuk</dc:creator>
      <dc:date>2013-12-10T22:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssh decryption after SSH server upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4664#M3433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a decyption profile attached to the ssl decypt policy ? What have you configured for unsupported mode checks and failure checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Set up a filter and run ssl counters to get more info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show counter global filter category ssl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deepak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 18:48:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4664#M3433</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2013-12-12T18:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssh decryption after SSH server upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4665#M3434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep an eye out for PAN OS 5.0.10. A fix for an issue with some SSH proxy sessions not working to OpenSSH servers versions &amp;gt; 6.2 is being published through fix # 57612&lt;/P&gt;&lt;P&gt;This fix, when available, may help you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2013 13:44:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4665#M3434</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-12-19T13:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssh decryption after SSH server upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4666#M3435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look in Rn for version 5.0.10, there is:&lt;/P&gt;&lt;P&gt;57612—SSH sessions to servers running OpenSSH version 6.2 or newer through SSH &lt;/P&gt;&lt;P&gt;Decryption were failing in some instances when the computed Diffie-Hellman key is &lt;/P&gt;&lt;P&gt;4096 bits. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Dec 2013 08:10:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4666#M3435</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-12-27T08:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ssh decryption after SSH server upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4667#M3436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've upgraded my PAN device even to PAN-OS 6.0, and still ssh decryption doesn't work properly.&lt;/P&gt;&lt;P&gt;I've tried with and without decryption profiles enabled.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Feb 2014 13:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-ssh-decryption-after-ssh-server-upgrade/m-p/4667#M3436</guid>
      <dc:creator>mariusz_sawczuk</dc:creator>
      <dc:date>2014-02-05T13:34:29Z</dc:date>
    </item>
  </channel>
</rss>

