<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decrypt error (soap) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226306#M65153</link>
    <description>&lt;P&gt;Yes, we are doing decrypt for this kind of sessions. This is the log view detailed. Where can i get more info about the root cause for this error???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought that we could be hitting this link:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Identify-Root-Cause-for-SSL-Decryption-Failure-Issues/ta-p/59445" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Identify-Root-Cause-for-SSL-Decryption-Failure-Issues/ta-p/59445&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura1.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16197iCECF8B0DF0AF8898/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Captura1.JPG" alt="Captura1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Aug 2018 15:42:12 GMT</pubDate>
    <dc:creator>BigPalo</dc:creator>
    <dc:date>2018-08-07T15:42:12Z</dc:date>
    <item>
      <title>Decrypt error (soap)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226278#M65148</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We realised that we are receiving decrypt errors accessing to O365 from inside to outside. We are doing decrypt in sessions. But we dont know why the sessions are finished with "decrypt-error".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16191i6F91338F4A0CB63D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="error.JPG" alt="error.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 12:54:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226278#M65148</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2018-08-07T12:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypt error (soap)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226303#M65152</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's likely because of Certificate Pinning, which the firewall can't actually transparently decrypt. If you view the associated session directly on the firewall it'll have a tad bit more information that may be helpful, such as if you are running into a proxy decrypt failure.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 15:37:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226303#M65152</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-07T15:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypt error (soap)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226306#M65153</link>
      <description>&lt;P&gt;Yes, we are doing decrypt for this kind of sessions. This is the log view detailed. Where can i get more info about the root cause for this error???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought that we could be hitting this link:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Identify-Root-Cause-for-SSL-Decryption-Failure-Issues/ta-p/59445" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Identify-Root-Cause-for-SSL-Decryption-Failure-Issues/ta-p/59445&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura1.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16197iCECF8B0DF0AF8898/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Captura1.JPG" alt="Captura1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 15:42:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226306#M65153</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2018-08-07T15:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypt error (soap)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226308#M65155</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The first line of the 'General' box will be the session id number. Through the CLI running 'show session id&amp;nbsp;&lt;EM&gt;session_id_number&lt;/EM&gt;' would give you a bit more information about what exactly caused the issue in the 'tracker stage firewall' section. You could be hitting a variety of issues with this, but the most common is due to an unsupported SSL protocol. You can verify this by viewing the global counters and seeing if it increments as you see these logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 15:48:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226308#M65155</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-07T15:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypt error (soap)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226363#M65167</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;A little strange actually is that the firewalls already sees the application soap which implies that the decryption already happened. In addition the sessions are too big already in my opinion. If a decryption error happens the sessions normally are smaller.&lt;/P&gt;&lt;P&gt;In addition to what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;wrote I would also do a packet capture and check if there is already data or if you see TLS handshake errors.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 20:26:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decrypt-error-soap/m-p/226363#M65167</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-07T20:26:07Z</dc:date>
    </item>
  </channel>
</rss>

