<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enabling TLS 1.1 in Decryption profile always allows 3DES even if unchecked in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173381#M54579</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/33813"&gt;@bfperez&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unchecking in the GUI seems to work fine.&lt;/P&gt;
&lt;P&gt;The xml file will also reflect&amp;nbsp;this config once it's committed :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;blah { 
     ssl-protocol-settings { 
                           enc-algo-3des no; &lt;BR /&gt;                           } 
     }&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem seems to be that the GUI doesn't "retain" this setting if you return to the same tab for a second time. &amp;nbsp;Notice how 3DES is re-checked even when it's not listed in the 'Encryption Algorithms'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="3DES is enabled." style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10936i56C88DD10C4E29ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="2017-08-28_10-30-17.jpg" alt="3DES is enabled." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;3DES is enabled.&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If&amp;nbsp;you click OK here and recommit then you might re-enable 3DES unintentionally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Eitherway I believe it might be a good idea to get TAC involved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Aug 2017 08:37:18 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2017-08-28T08:37:18Z</dc:date>
    <item>
      <title>Enabling TLS 1.1 in Decryption profile always allows 3DES even if unchecked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173170#M54555</link>
      <description>&lt;P&gt;Scenario:&lt;/P&gt;&lt;P&gt;Decryption profile for traffic from the internet to GlobalProtect IP along with an SSL/TLS Service Profile for GlobalProtect, both set to TLS 1.1 or above; Decryption profile has 3DES unchecked.&lt;/P&gt;&lt;P&gt;PA-5020, 7.1.10&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Scans from sites like ssllabs.com will show that 3DES is still enabled.&amp;nbsp; Only changing one of the profiles to TLS 1.2 stops this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can be repeated with decryption profiles that inspect inbound traffic to a test server that still allows 3DES and TLS 1.1+.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a side note, anytime I change the decryption profile dropdown from TLS 1.2 to TLS 1.1 to TLS 1.0, the 3DES box is checked automatically and I have to uncheck it.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 00:50:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173170#M54555</guid>
      <dc:creator>bfperez</dc:creator>
      <dc:date>2017-08-25T00:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling TLS 1.1 in Decryption profile always allows 3DES even if unchecked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173213#M54557</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/33813"&gt;@bfperez&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd recommend opening a TAC case with the results of ssllabs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, I'm seeing the same behaviour with the 3DES checkbox on both PAN-OS 7.1 and 8.0 so I'm thinking this is currenlty the expected behaviour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 11:53:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173213#M54557</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-08-25T11:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling TLS 1.1 in Decryption profile always allows 3DES even if unchecked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173228#M54559</link>
      <description>&lt;P&gt;Cool, it is possible to add a decryption profile to global protect traffic? On the same firewall or is this only possible if you have another PA in front of the global protect portal/gateway where you do inbound decryption?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 14:24:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173228#M54559</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-25T14:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling TLS 1.1 in Decryption profile always allows 3DES even if unchecked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173261#M54562</link>
      <description>&lt;P&gt;We just have an HA pair that does all inbound decryption AND houses the GP Portals and Gateways.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a decryption profile setup for traffic from the internet to the portals/gatways just like the decryption profiles for other inbound traffic, and it works.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 19:12:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173261#M54562</guid>
      <dc:creator>bfperez</dc:creator>
      <dc:date>2017-08-25T19:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling TLS 1.1 in Decryption profile always allows 3DES even if unchecked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173265#M54563</link>
      <description>&lt;P&gt;You could try to "uncheck" 3DES from the CLI, maybe this works (if it is a bug in the webUI.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 20:18:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173265#M54563</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-25T20:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling TLS 1.1 in Decryption profile always allows 3DES even if unchecked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173283#M54568</link>
      <description>&lt;P&gt;Besides the fact that there seems to be a bug: Is this a real problem? Wouldn't it make more sense to only enable TLS1.2 as there are almost 0 clients that stop at TLS1.1 and do not support TLS1.2&lt;/P&gt;</description>
      <pubDate>Sat, 26 Aug 2017 11:06:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173283#M54568</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-26T11:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling TLS 1.1 in Decryption profile always allows 3DES even if unchecked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173381#M54579</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/33813"&gt;@bfperez&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unchecking in the GUI seems to work fine.&lt;/P&gt;
&lt;P&gt;The xml file will also reflect&amp;nbsp;this config once it's committed :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;blah { 
     ssl-protocol-settings { 
                           enc-algo-3des no; &lt;BR /&gt;                           } 
     }&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem seems to be that the GUI doesn't "retain" this setting if you return to the same tab for a second time. &amp;nbsp;Notice how 3DES is re-checked even when it's not listed in the 'Encryption Algorithms'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="3DES is enabled." style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10936i56C88DD10C4E29ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="2017-08-28_10-30-17.jpg" alt="3DES is enabled." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;3DES is enabled.&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If&amp;nbsp;you click OK here and recommit then you might re-enable 3DES unintentionally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Eitherway I believe it might be a good idea to get TAC involved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 08:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173381#M54579</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-08-28T08:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling TLS 1.1 in Decryption profile always allows 3DES even if unchecked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173435#M54587</link>
      <description>&lt;P&gt;Agreed that it's not a real problem.&amp;nbsp; I was just trying to move one step at a time in case we had some oddball app/user that could only do 1.1 or lower.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 15:04:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-tls-1-1-in-decryption-profile-always-allows-3des-even/m-p/173435#M54587</guid>
      <dc:creator>bfperez</dc:creator>
      <dc:date>2017-08-28T15:04:58Z</dc:date>
    </item>
  </channel>
</rss>

