<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption in different countries? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/292456#M77388</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73975"&gt;@Rievax&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Decrypt-error tells us the ciphers used by the web server are not supported/matched with the ciphers enabled on decryption profile. Can you verify that.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards, Nagarjuna&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Oct 2019 04:14:23 GMT</pubDate>
    <dc:creator>nagarjuna.b</dc:creator>
    <dc:date>2019-10-11T04:14:23Z</dc:date>
    <item>
      <title>SSL Decryption in different countries?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/292398#M77381</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Starting to deploy 100+ firewalls worldwide. Have configured SSL decryption for General Browsing rule.&lt;/P&gt;&lt;P&gt;A template has been configured in Panorama, so they all have the exact same setup.&lt;BR /&gt;&lt;BR /&gt;North America and Europe locations I tested are OK. Tried a Brazil office yesterday and if decryption is enabled, for very basic sites like UPS and Fedex, it becomes super slow - sometimes does not even finish loading the page at all. As soon as I disable decryption in this Brazilian branch, all seems to be working fine. Looked into the logs and there were many failures (decrypt-error) for the Session-End Reason. I do not have similar logs in other branch offices in North America and Europe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be your input on that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 19:40:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/292398#M77381</guid>
      <dc:creator>Rievax</dc:creator>
      <dc:date>2019-10-10T19:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption in different countries?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/292456#M77388</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73975"&gt;@Rievax&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Decrypt-error tells us the ciphers used by the web server are not supported/matched with the ciphers enabled on decryption profile. Can you verify that.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards, Nagarjuna&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 04:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/292456#M77388</guid>
      <dc:creator>nagarjuna.b</dc:creator>
      <dc:date>2019-10-11T04:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption in different countries?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/292567#M77399</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76959"&gt;@nagarjuna.b&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This morning, I did re-enable decryption again for a specific test workstation but had none of those Decrypt-errors I had yesterday at implementation time... No clue from where is was coming. To answer more specifically your question, the Decryption profile is quite open (like the Default) and the web site goes with&amp;nbsp;&lt;SPAN&gt;TLS 1.2, ECDHE_RSA with P-256, and AES_256_GCM... which is exactly what PA generates when decryption is enabled.&amp;nbsp;That being said, the loading page delays are still there.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Focusing on UPS.COM web site, when decryption is enabled in this particular location (big city in Brazil), it takes 5 seconds to load the root site (/) and 5 to 7 minutes to load some &lt;STRONG&gt;JPGs and GIF&lt;/STRONG&gt; files (numbers are coming from Developer Tools in Firefox / Chrome) - making the page virtually hang. Disabling&amp;nbsp;decryption makes this site display in about a second. I did not see any kind of related information in Data Filtering / Wildfire Submissions logs. In other Office Locations around the globe that I tested, I did not have these delays with decryption enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Interestingly, many other sites are just working OK but also notice delays in loading (or non-loading) &lt;STRONG&gt;images&lt;/STRONG&gt;. I though that could be an interesting point.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any help / clues are appreciated. Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;R.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 13:50:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/292567#M77399</guid>
      <dc:creator>Rievax</dc:creator>
      <dc:date>2019-10-11T13:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption in different countries?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/292671#M77409</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Have you looked at the logs to make sure nothing is getting blocked? OR taken any pcaps to see if there are a lot of retransmits or other issues?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just some thoughts.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 20:16:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/292671#M77409</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-10-11T20:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption in different countries?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/293304#M77559</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the late answer as had to test in other places to get a base reference.&lt;/P&gt;&lt;P&gt;So I went with the suggestion to capture packets (at the PA Firewall transmit stage) and noticed that in Brazil, I have lots of fragmentation happening:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 926px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21840i397C4FEC422D2F3E/image-dimensions/926x148/is-moderation-mode/true?v=v2" width="926" height="148" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I will try to reach the ISP but it seems from the Cisco router suggested configuration that the MTU is 1492. I confirmed that by using ping packets of 1464 (+28 of overhead) - higher are failing:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_1.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21841i6607DA7F4391E09F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_1.png" alt="clipboard_image_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Our WAN tech tried to manually set 1500 but the end-result is the same. We will have to talk to the ISP now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That being said, could this be the reason why decryption is failing? Some odd issues when the PA tries to re-assemble the packets and scan the images? Quite new to PA and decryption, so I definitely don't know that answer - yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, thanks for any comments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;R.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2019 19:28:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-in-different-countries/m-p/293304#M77559</guid>
      <dc:creator>Rievax</dc:creator>
      <dc:date>2019-10-18T19:28:59Z</dc:date>
    </item>
  </channel>
</rss>

