<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption &amp;amp; not working VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147579#M49406</link>
    <description>&lt;P&gt;Thanks both for your answers. We will plan a maintenance window to update both firewalls to their latest version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any recommendations to which version? I noticed that version 8.0.0 has been released recently.&lt;/P&gt;&lt;P&gt;Would it be wise to stick with 7.1.8 for now?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remko&lt;/P&gt;</description>
    <pubDate>Tue, 14 Mar 2017 08:04:01 GMT</pubDate>
    <dc:creator>Indorama_Ventures</dc:creator>
    <dc:date>2017-03-14T08:04:01Z</dc:date>
    <item>
      <title>SSL decryption &amp; not working VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147376#M49384</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We wittnessed a very strange phenomenon this morning.&lt;/P&gt;&lt;P&gt;First we received a call that our VPN gateway was not accepting any VPN connections.&lt;/P&gt;&lt;P&gt;At the same time we received calls that certain websites were not accessible. These websites had in common that they were SSL encrypted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 2 PA-500 firewalls with&amp;nbsp;a HA configuration.&lt;BR /&gt;SSL decryption is enabled for certain networks (workstations). SSL decryption uses a different certificate than our VPN gateway.&lt;/P&gt;&lt;P&gt;Both certificates are valid.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as we turned off SSL decryption, the VPN gateway started to accept connections.&lt;/P&gt;&lt;P&gt;When we turned SSL decryption back on we noticed that some websites were decrypted while others were not.&lt;/P&gt;&lt;P&gt;The sites that were not decrypted should have been decrypted. They were not in the "Do-not-Decrypt" list.&lt;/P&gt;&lt;P&gt;To be&amp;nbsp;certain the firewall was doing the job right, &amp;nbsp;I deleted the certificate cache on my browser. I also visited sites that were SSL encrypted which I had not visited before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are a bit puzzled what happened here. Currently we have SSL decryption turned off&amp;nbsp;but would like to have it on again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA-500 is&amp;nbsp;a few software versions behind. Currently on version 7.1.2&lt;/P&gt;&lt;P&gt;I have tried to find anything related in the release notes of the newer versions that might indicate a problem with our current version. I was not able to find this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what might be going on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remko&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 10:09:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147376#M49384</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2017-03-13T10:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption &amp; not working VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147418#M49394</link>
      <description>&lt;P&gt;Per the description sounds like a buffer depletion, I just checked the release notes and there are a couple of fixes on that but I'd recommend you to collect a tech support and open a TAC case to get the right diagnostic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Gerardo.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 15:47:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147418#M49394</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2017-03-13T15:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption &amp; not working VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147420#M49396</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45031"&gt;@Indorama_Ventures&lt;/a&gt;&amp;nbsp;it does sound like buffer depletion, which is multiple fixes were made in later releases. I would recommend upgrading, 7.1.2 was very early in the 7.1 lifecycle and therefore has quite a few bugs that weren't patched until later versions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 15:54:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147420#M49396</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-13T15:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption &amp; not working VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147579#M49406</link>
      <description>&lt;P&gt;Thanks both for your answers. We will plan a maintenance window to update both firewalls to their latest version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any recommendations to which version? I noticed that version 8.0.0 has been released recently.&lt;/P&gt;&lt;P&gt;Would it be wise to stick with 7.1.8 for now?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remko&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 08:04:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147579#M49406</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2017-03-14T08:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption &amp; not working VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147580#M49407</link>
      <description>&lt;P&gt;I think yes 7.1.8 is the one we also decided to go for now but to be fair you never know which release will work well for your environment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 08:44:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147580#M49407</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-14T08:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption &amp; not working VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147627#M49411</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45031"&gt;@Indorama_Ventures&lt;/a&gt;&amp;nbsp;personally I would not run 8.0 in a production enviroment at all; but that's just me. Stick with 7.1.8 and you shouldn't run into any issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 14:18:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-amp-not-working-vpn/m-p/147627#M49411</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-14T14:18:38Z</dc:date>
    </item>
  </channel>
</rss>

