<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cipher suites decryption 7.1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78932#M43079</link>
    <description>&lt;P&gt;Thanks for your help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Turns out in the small print the EDHC ciphers are only supported in SSL forward proxy decryption, not inbound, which is why they don't work with the current setup. So, although Palo state that certain ciphers are now supported in 7.1, it's best not to just go by the new cipher suites added in 7.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's in very small print in the Decryption Profile under Protocol Settings:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="protocol settings.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4244i17ABF3F4858523FE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="protocol settings.png" alt="protocol settings.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, thank you again for your help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Jack&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jun 2016 15:05:57 GMT</pubDate>
    <dc:creator>Jack_Howells</dc:creator>
    <dc:date>2016-06-01T15:05:57Z</dc:date>
    <item>
      <title>Cipher suites decryption 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78911#M43070</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Configuring inbound SSL inspection on 7.1, decryption does not work with the newly supported cipher suites shown in the document below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Supported-ciphers/ta-p/71969" target="_blank"&gt;https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Supported-ciphers/ta-p/71969&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only the cipher suites shown in the document below again work.&amp;nbsp;The document above states that&amp;nbsp;&lt;SPAN&gt;ECDHE should work but it does not. &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/SSL-Decryption-Not-Working-due-to-Unsupported-Cipher-Suites/ta-p/55543" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/SSL-Decryption-Not-Working-due-to-Unsupported-Cipher-Suites/ta-p/55543&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could anyone provide some advice for this situation?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 09:40:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78911#M43070</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-01T09:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cipher suites decryption 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78918#M43072</link>
      <description>&lt;P&gt;Hi Jack&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there are some limitations for ECDHE, did you take these into account:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; For ECDHE, only named curves.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; For ECDHE EC_point format, only uncompressed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and that your cipher matches one of the listed modes (some E&lt;STRONG&gt;CDHEmodes are not supported)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 09:48:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78918#M43072</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-06-01T09:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cipher suites decryption 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78926#M43076</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cipher suites I'm using on the F5 load balancer are:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-CBC-SHA:ECDHE-RSA-AES128-CBC-SHA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this match the limitations for ECDHE?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards&lt;/P&gt;
&lt;P&gt;Jack&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 10:54:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78926#M43076</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-01T10:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cipher suites decryption 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78928#M43077</link>
      <description>&lt;P&gt;Hi Jack&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Those appear to match... you could try setting up a packet-diag with log features 'flow basic' and 'proxy all' for 1 single source, this may help shine some light on why it isn't working as expected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check out this article for some help with the packet-diag:&amp;nbsp;&lt;A title="Getting Started: Flow Basic" href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Flow-Basic/ta-p/72556" target="_blank"&gt;Getting Started: Flow Basic&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 11:18:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78928#M43077</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-06-01T11:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cipher suites decryption 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78932#M43079</link>
      <description>&lt;P&gt;Thanks for your help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Turns out in the small print the EDHC ciphers are only supported in SSL forward proxy decryption, not inbound, which is why they don't work with the current setup. So, although Palo state that certain ciphers are now supported in 7.1, it's best not to just go by the new cipher suites added in 7.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's in very small print in the Decryption Profile under Protocol Settings:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="protocol settings.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4244i17ABF3F4858523FE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="protocol settings.png" alt="protocol settings.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, thank you again for your help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Jack&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 15:05:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cipher-suites-decryption-7-1/m-p/78932#M43079</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-01T15:05:57Z</dc:date>
    </item>
  </channel>
</rss>

