<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH decrypt and not decrypt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212236#M61910</link>
    <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an ERP server on the inside which must be access from supplier via SSH. Trying both using proxy and no decrypt but always getting Aged out in traffic monitor.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have access to the ERP system but I got the routing printed and it looks ok.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what would be causing aged out? Firewall in the *nix machine?&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Trying to get access to the *nix machine and have a look)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Ronnie&lt;/P&gt;</description>
    <pubDate>Mon, 30 Apr 2018 08:02:44 GMT</pubDate>
    <dc:creator>RonnieAxelsson</dc:creator>
    <dc:date>2018-04-30T08:02:44Z</dc:date>
    <item>
      <title>SSH decrypt and not decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212236#M61910</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an ERP server on the inside which must be access from supplier via SSH. Trying both using proxy and no decrypt but always getting Aged out in traffic monitor.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have access to the ERP system but I got the routing printed and it looks ok.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what would be causing aged out? Firewall in the *nix machine?&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Trying to get access to the *nix machine and have a look)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Ronnie&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 08:02:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212236#M61910</guid>
      <dc:creator>RonnieAxelsson</dc:creator>
      <dc:date>2018-04-30T08:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decrypt and not decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212255#M61913</link>
      <description>&lt;P&gt;Sounds like a good theory that the issue is on the server since you can see the session is permitted on the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could also do a packet capture of the login attempt, this might give you more specific information on where the process is failing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/monitor/monitor-packet-capture" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/monitor/monitor-packet-capture&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 10:03:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212255#M61913</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-04-30T10:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decrypt and not decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212357#M61931</link>
      <description>&lt;P&gt;in addition to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas&lt;/a&gt;&amp;nbsp;said,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can run tcpdump on the *nix machine as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SInce it is hosted inside, i am assuming you have made sure of NAT to be working correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;~HTH&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 20:47:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212357#M61931</guid>
      <dc:creator>Harshit</dc:creator>
      <dc:date>2018-04-30T20:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decrypt and not decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212367#M61934</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is this over a VPN tunnel? Do the traceroutes look ok, if allowed? When you view the traffic logs, where is it getting dropped as opposed to how your rule is written to allow the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 22:09:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212367#M61934</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-04-30T22:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSH decrypt and not decrypt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212561#M61973</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Got access to the *nix machine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Guess what, there was an firewall implmeneted (that the supplier didn't know about)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So when this was resolved everything works as expeceted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for all the replies.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Ronnie&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 09:33:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decrypt-and-not-decrypt/m-p/212561#M61973</guid>
      <dc:creator>RonnieAxelsson</dc:creator>
      <dc:date>2018-05-02T09:33:29Z</dc:date>
    </item>
  </channel>
</rss>

