<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Version in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/229103#M65866</link>
    <description>&lt;P&gt;I like the workaround described by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;, but if you do that there are some things that you need to pay attention to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If you do TLS decryption then make sure that you activate the checkbox in the custom app for continue scanning for other apps. Otherwise you will loose a big part of the visibility that paloalto provides. But at the same time you need to enable session start logs because you will not see the custom app in the logs.&lt;/LI&gt;&lt;LI&gt;If you don't decrypt traffic then you don't need to enable the checlbox to scan for other apps but at least a small part of the visibility will also go away.&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Sat, 01 Sep 2018 14:17:12 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-09-01T14:17:12Z</dc:date>
    <item>
      <title>SSL Version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/228649#M65732</link>
      <description>&lt;P&gt;Is there any way for the traffic logs to display the SSL/TLS version that's in use for a particular flow? I don't see the data in the traffic logs or in the session info at the CLI.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 23:47:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/228649#M65732</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-08-28T23:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/228656#M65733</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This information is written to any log file; if it's a desired feature I would raise the request with your SE.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 23:57:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/228656#M65733</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-28T23:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/228762#M65762</link>
      <description>&lt;P&gt;So the info is written to a log file and it just needs to be exposed so that it can be viewed? Or it's not written to any log file and a request should be submitted to an SE for this info to be captured?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 14:51:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/228762#M65762</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-08-29T14:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/228764#M65764</link>
      <description>&lt;P&gt;That information is&amp;nbsp;not written to a log file, as far as I know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a workaround, you may be able to define custom applications that identify the different versions from header information, and report on the use of those...&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 15:17:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/228764#M65764</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-08-29T15:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/229103#M65866</link>
      <description>&lt;P&gt;I like the workaround described by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;, but if you do that there are some things that you need to pay attention to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If you do TLS decryption then make sure that you activate the checkbox in the custom app for continue scanning for other apps. Otherwise you will loose a big part of the visibility that paloalto provides. But at the same time you need to enable session start logs because you will not see the custom app in the logs.&lt;/LI&gt;&lt;LI&gt;If you don't decrypt traffic then you don't need to enable the checlbox to scan for other apps but at least a small part of the visibility will also go away.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sat, 01 Sep 2018 14:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-version/m-p/229103#M65866</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-01T14:17:12Z</dc:date>
    </item>
  </channel>
</rss>

