<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decryption causing more sites to fail in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76734#M42408</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More and more web servers are dropping support for RSA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://notepad-plus-plus.org/" target="_blank"&gt;https://notepad-plus-plus.org/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is just one of them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ECDHE ciphers are supported for decryption with the release of 7.1.0. If you are encountering problems where the websites are unable to be decrypted due to unsupported ciphers then it would be worth upgrading to take advantage of the new features.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
    <pubDate>Wed, 20 Apr 2016 13:39:14 GMT</pubDate>
    <dc:creator>bmorris1</dc:creator>
    <dc:date>2016-04-20T13:39:14Z</dc:date>
    <item>
      <title>Decryption causing more sites to fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76732#M42407</link>
      <description>&lt;P&gt;Just floating this out to the community. We have had decryption enabled for the past 2 years. In the last 6 months we are adding a new site to the no decrypt category about once a week. We are up to 94 sites that it can't decrypt. Yesterday it was Office365 exchange that stopped woeking, today was the kicker with microsoft updates failing even though we have always had update.microsoft.com in the list not to decrypt. Last week we added Jimmy John's wich we have been using for ever. Is this happening to others?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 13:01:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76732#M42407</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2016-04-20T13:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption causing more sites to fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76734#M42408</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More and more web servers are dropping support for RSA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://notepad-plus-plus.org/" target="_blank"&gt;https://notepad-plus-plus.org/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is just one of them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ECDHE ciphers are supported for decryption with the release of 7.1.0. If you are encountering problems where the websites are unable to be decrypted due to unsupported ciphers then it would be worth upgrading to take advantage of the new features.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 13:39:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76734#M42408</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-04-20T13:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption causing more sites to fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76736#M42409</link>
      <description>&lt;P&gt;I don't think Jimmy John's is the RSA support issue, because we're cracking it and it's working for us.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JimmyJohns.png" style="width: 345px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3620i2FDE45138677C5FB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="JimmyJohns.png" alt="JimmyJohns.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might want to review your decyption profile&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28274"&gt;@craymond﻿&lt;/a&gt;&amp;nbsp;and make sure you've got support for unsupported ciphers. &amp;nbsp;Though there is a known issue that even though you've got the box checked it still doesn't work, and there for requires admins to bypass SSL Interception for that particular site. &amp;nbsp;(For reasons like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1﻿&lt;/a&gt;&amp;nbsp;said, Palo's lack of support of certain ciphers on code versions less than 7.1.X) &amp;nbsp;Sites have been ramping up using stronger ciphers that until 7.1.X palo didn't support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also could it be possible that your hardware is running out of resources to support the increased use of SSL across the Internet? &amp;nbsp;Hardware purchased 3 years ago might be reaching it's limit since pretty much every site is SSL now.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 13:53:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76736#M42409</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-20T13:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption causing more sites to fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76743#M42413</link>
      <description>&lt;P&gt;If it is a resource issue then you can quickly check the pools&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; debug dataplane pool statistics&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_41.png" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3621i39ECC3C11F76F3D1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_41.png" alt="Screenshot_41.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also check the counters that match the proxy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show counter global | match proxy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would be worth clearing the exclude cache as well, but you'll see the usage in the pool output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; debug dataplane reset ssl-decrypt exclude-cache&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 14:16:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76743#M42413</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-04-20T14:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption causing more sites to fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76765#M42419</link>
      <description>&lt;P&gt;We have it scheduled to upgrade to 7.1, will see if this resolves the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 18:05:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76765#M42419</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2016-04-20T18:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption causing more sites to fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76770#M42423</link>
      <description>&lt;P&gt;There are quite a few "known issues" with both 7.1.0 and 7.1.1, you might want to evaluate and make sure it's stable for your enviornment.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 20:03:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/76770#M42423</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-04-20T20:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption causing more sites to fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/77209#M42545</link>
      <description>&lt;P&gt;Thank you. I will be contacting my SE to discuss upgrade suggestions.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 13:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-causing-more-sites-to-fail/m-p/77209#M42545</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2016-04-28T13:14:04Z</dc:date>
    </item>
  </channel>
</rss>

