<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/845#M655</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to add guys content version 463 has been released which contains the SSLv3 poodle vulnerability signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Oct 2014 17:03:46 GMT</pubDate>
    <dc:creator>bat</dc:creator>
    <dc:date>2014-10-16T17:03:46Z</dc:date>
    <item>
      <title>Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/838#M648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a case where customer needs to disable SSL 3.0 on an interface and just use SSL 1.0 and 2.0 for both device management and GP. Is this possible? if so then how? Is there any other way apart from disabling the entire SSL feature on the interface? Kindly Advice&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2014 17:24:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/838#M648</guid>
      <dc:creator>mrafi</dc:creator>
      <dc:date>2014-10-15T17:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/839#M649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/29222"&gt;mrafi&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not tested this but you can try creating a custom vulnerability with ssl-rsp-version 3 and block it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="16321" alt="sslv3.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16321_sslv3.JPG" style="height: 265px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above vulnerability will only be effective for traffic going through dataplane port so if you are accessing management directly (without going dataplane port) this will not help for disabling SSLv3 on management interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will keep you posted if I get a chance to try this in lab&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2014 17:29:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/839#M649</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-15T17:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/840#M650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mrafi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can not disable SSLv3 by any command or configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, you may want to try custom vuln. signature mentioned above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2014 17:43:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/840#M650</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-15T17:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/841#M651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/29222"&gt;mrafi&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just tested this in my lab and it works &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to specify the decimal value for SSL 3.0 hexadecimal code (0x0300) which is 768.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="sslv3_decimal.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16325_sslv3_decimal.JPG" style="height: 227px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2014 18:45:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/841#M651</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-15T18:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/842#M652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mrafi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will stop SSLv3 on Data port only, for that you will have to configure custom vuln profile in policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will not help to stop SSLv3 on Management interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2014 19:33:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/842#M652</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-15T19:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/843#M653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mrafi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just FYI...&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.networkworld.com/article/2833937/security/security-experts-warn-of-poodle-attack-against-ssl-30.html" style="font-size: 10pt; line-height: 1.5em;" title="http://www.networkworld.com/article/2833937/security/security-experts-warn-of-poodle-attack-against-ssl-30.html"&gt;http://www.networkworld.com/article/2833937/security/security-experts-warn-of-poodle-attack-against-ssl-30.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2014 20:17:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/843#M653</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-15T20:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/844#M654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I created a custom signature like &lt;SPAN class="j-post-author"&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1246" data-externalid="" data-presence="null" data-userid="28201" data-username="csharma" href="https://live.paloaltonetworks.com/people/csharma"&gt;csharma&lt;/A&gt; &lt;/STRONG&gt;suggested and I can confirm that it works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="j-post-author"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="j-post-author"&gt;Although, it does not seem to work if you are decrypting the SSL traffic via Palo Alto.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2014 15:23:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/844#M654</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2014-10-16T15:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/845#M655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to add guys content version 463 has been released which contains the SSLv3 poodle vulnerability signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2014 17:03:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/845#M655</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-16T17:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/846#M656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No you can not disable this, the version is negotiated by the end-host and server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Vulnerability signature which is provided will not be applied to traffic destined to&amp;nbsp; firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example: people from DMZ are tried to manage firewall on firewall's DMZ interface, the signature will not be enough to identify ssl3, because content inspection is not applied when traffic is destined to firewall and not passing through the firewall. The same will apply to GP. we would not be able to identify this when SSL connection terminates on untrust interface of firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The work around while we wait for engineering is to host the service on loopback. Because when the service is hosted on loopback (different zone). This will make packet pass though the CTD engine of firewall like regular traffic to detect vulnerability.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Sai&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Oct 2014 00:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/846#M656</guid>
      <dc:creator>Sai_Tumuluri</dc:creator>
      <dc:date>2014-10-31T00:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/847#M657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;wow, so PA cant disable sslv3 ... thats not good. I know the sig can protect but common,,,, we cant pick protocols/ciphers on an enterprise class firewall ..?? AND its based on Linux right? so PA went out of its way to make it so we cant do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Oct 2014 16:03:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/847#M657</guid>
      <dc:creator>choff123</dc:creator>
      <dc:date>2014-10-31T16:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/848#M658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why does the PA NOT detect SSLv3 when it's set to decrypt the passing traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what I did to test...&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; I forced my browser to user ONLY SSLv3.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Set Threat ID 36815(SSLv3 Found in Server Response) to "drop-all-packets".&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Browsed to web server behind the PA and page loaded fine.&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; Wireshark capture shows only SSLv3 being used.&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; Not detected in PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I tried web traffic that is not being decrypted and the PA detected and blocked the SSLv3 attempt.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 14:44:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/848#M658</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2014-11-04T14:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Specifically Disable SSL 3.0 on a Palo Alto Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/849#M659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I's suppose the PA to be able to adjust the SSL/TLS Versions allowed in SSL hello messages when performing SSL Decryption since it is acting as the clientside towards the WebServer ?!&lt;/P&gt;&lt;P&gt;Why is there no way to infuence this with a Decryption Profile?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 10:13:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-specifically-disable-ssl-3-0-on-a-palo-alto/m-p/849#M659</guid>
      <dc:creator>ruby</dc:creator>
      <dc:date>2014-11-19T10:13:09Z</dc:date>
    </item>
  </channel>
</rss>

