<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL Website won't load with decryption enabled in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-website-won-t-load-with-decryption-enabled/m-p/187019#M56973</link>
    <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of my users was trying to go to:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://mn.b3benchmarking.com/Launch" target="_blank"&gt;https://mn.b3benchmarking.com/Launch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have SSL forward proxy enabled.&amp;nbsp; If I exclude the site from decryption is comes up fine.&amp;nbsp; We are not using any decryption profiles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone tell my why the sites won't come up?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did run a check using&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ssllabs.com/ssltest/analyze.html?d=mn.b3benchmarking.com" target="_blank"&gt;https://www.ssllabs.com/ssltest/analyze.html?d=mn.b3benchmarking.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but am not sure how to&amp;nbsp;interpret the output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dannon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Nov 2017 21:59:31 GMT</pubDate>
    <dc:creator>dannon</dc:creator>
    <dc:date>2017-11-14T21:59:31Z</dc:date>
    <item>
      <title>SSL Website won't load with decryption enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-website-won-t-load-with-decryption-enabled/m-p/187019#M56973</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of my users was trying to go to:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://mn.b3benchmarking.com/Launch" target="_blank"&gt;https://mn.b3benchmarking.com/Launch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have SSL forward proxy enabled.&amp;nbsp; If I exclude the site from decryption is comes up fine.&amp;nbsp; We are not using any decryption profiles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone tell my why the sites won't come up?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did run a check using&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ssllabs.com/ssltest/analyze.html?d=mn.b3benchmarking.com" target="_blank"&gt;https://www.ssllabs.com/ssltest/analyze.html?d=mn.b3benchmarking.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but am not sure how to&amp;nbsp;interpret the output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dannon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 21:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-website-won-t-load-with-decryption-enabled/m-p/187019#M56973</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2017-11-14T21:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Website won't load with decryption enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-website-won-t-load-with-decryption-enabled/m-p/187139#M56991</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5565"&gt;@dannon&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What PAN-OS are you running ? Note that older PAN-OS versions have less&amp;nbsp;supported ciphers :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/global/compatibility-matrix/supported-cipher-suites" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/global/compatibility-matrix/supported-cipher-suites&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The site you mentioned seems to support only&amp;nbsp;older protocols&amp;nbsp; (no TLS 1.1, 1.2 or 1.3).&amp;nbsp; You might have configured a Min version on your firewall.&lt;/P&gt;
&lt;P&gt;Also you might have configured your decryption in such a way to block unsupported versions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you checked the global counters for possible&amp;nbsp;issues ?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The "show counter global"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command will show if a cipher suite is unsupported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With a PCAP filter applied and using delta counters:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; show counter global filter packet-filter yes delta yes&lt;/PRE&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt; show counter global filter delta yes | match "ssl_server_cipher_not_supported"
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 09:17:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-website-won-t-load-with-decryption-enabled/m-p/187139#M56991</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-11-15T09:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Website won't load with decryption enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-website-won-t-load-with-decryption-enabled/m-p/187244#M57007</link>
      <description>&lt;P&gt;After looking at the SSL Labs report for this website and seeing all the issues...&amp;nbsp; Try getting in contact with the website owner to fix their site (I have had to do this myself on several occasions).&amp;nbsp; Then, if they don't fix their site and you still require access, create a decryption policy that excludes this one URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running PAN-OS 8.0.5, and the webpage doesn't load for me either.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 18:08:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-website-won-t-load-with-decryption-enabled/m-p/187244#M57007</guid>
      <dc:creator>CTW1983</dc:creator>
      <dc:date>2017-11-15T18:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Website won't load with decryption enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-website-won-t-load-with-decryption-enabled/m-p/187246#M57008</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We run 8.0.5 and I'm glad it's not unique to our setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have excluded the website for the time being.&lt;/P&gt;&lt;P&gt;Dannon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 18:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-website-won-t-load-with-decryption-enabled/m-p/187246#M57008</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2017-11-15T18:46:15Z</dc:date>
    </item>
  </channel>
</rss>

