<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content-Filter and Decryption - ERR_SSL_PROTOCOL_ERROR in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1081#M841</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Pstriker,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please verify, what version of TLS you are getting during SSL handshake. The SSL versions supported by PAN-OS 5.0.x &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;are&lt;/SPAN&gt;&lt;/SPAN&gt;: SSLv3, TLS1.0, and TLS1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are getting a connection on TLS version 1.2, you can change the browser settings to use a lower TLS version and let us know the result. Also make sure, below mentioned settings is unchecked if you have a "decryption profile" &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;configured&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; on your firewall during the test.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="13727" alt="Decryption profile.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13727_Decryption profile.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/5363"&gt;SSL Decrypt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 31 May 2014 13:53:07 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-05-31T13:53:07Z</dc:date>
    <item>
      <title>Content-Filter and Decryption - ERR_SSL_PROTOCOL_ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1079#M839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see a strange problem with the combination of content-filtering and decryption:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Decryption is on&lt;/P&gt;&lt;P&gt;- Facebook is declared as "block-continue"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I open "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.facebook.de" rel="nofollow"&gt;http://www.facebook.de&lt;/A&gt;&lt;SPAN&gt;" the block-continue-page appears - pressing continue forwards me to "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.facebook.com" rel="nofollow"&gt;https://www.facebook.com&lt;/A&gt;&lt;SPAN&gt;" and everything is fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;30 minutes later, I try to access "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.facebook.com" rel="nofollow"&gt;https://www.facebook.com&lt;/A&gt;&lt;SPAN&gt;", but instead of showing the block-continue-page, the browser (tested with Firefox and Chrome) does just show&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSL Connection Error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #a0a0a0; font-family: Helvetica, Arial, sans-serif; background-color: #f9f9f9;"&gt;ERR_SSL_PROTOCOL_ERROR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only workaround, I found was to access the "http-site" of facebook to get back the block-continue-page of my PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you ever see that behaviour?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using software release 5.0.11 at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 May 2014 08:38:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1079#M839</guid>
      <dc:creator>PStricker</dc:creator>
      <dc:date>2014-05-31T08:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Filter and Decryption - ERR_SSL_PROTOCOL_ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1080#M840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This sounds like a bug.&amp;nbsp; I don't see anything like this on the list of addressed issues in PAN-OS 5.0.12 either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would open a ticket to get this reported and into the bug database for a fix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 May 2014 11:28:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1080#M840</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-05-31T11:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Filter and Decryption - ERR_SSL_PROTOCOL_ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1081#M841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Pstriker,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please verify, what version of TLS you are getting during SSL handshake. The SSL versions supported by PAN-OS 5.0.x &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;are&lt;/SPAN&gt;&lt;/SPAN&gt;: SSLv3, TLS1.0, and TLS1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are getting a connection on TLS version 1.2, you can change the browser settings to use a lower TLS version and let us know the result. Also make sure, below mentioned settings is unchecked if you have a "decryption profile" &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;configured&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; on your firewall during the test.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="13727" alt="Decryption profile.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13727_Decryption profile.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/5363"&gt;SSL Decrypt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 May 2014 13:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1081#M841</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-31T13:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Filter and Decryption - ERR_SSL_PROTOCOL_ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1082#M842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI: &lt;/P&gt;&lt;P&gt;Google Chrome: In order to enable TLS 1.0 in Chrome do the &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;following&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;1. Click the wrench icon: &lt;/P&gt;&lt;P&gt;2. Choose Options &lt;/P&gt;&lt;P&gt;3. Select "Under the Hood" Tab &lt;/P&gt;&lt;P&gt;4. Click Change proxy settings &lt;/P&gt;&lt;P&gt;5. Select "Advanced" Tab &lt;/P&gt;&lt;P&gt;6. Scroll down and check TLS 1.0 &lt;/P&gt;&lt;P&gt;7. Close and restart all open browsers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 May 2014 13:54:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1082#M842</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-31T13:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Filter and Decryption - ERR_SSL_PROTOCOL_ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1083#M843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hulk!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked my settings: TLS 1.0 is already enabled, but block-continue-pages are not displayed for https-sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My decryption profile does not block &lt;SPAN style="color: #222222; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ebedee;"&gt;sessions with unsupported cipher suites. I double-checked this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think, the problem is the combination of content filter and decryption:&lt;/P&gt;&lt;P&gt;- Content-Filter is working fine&lt;/P&gt;&lt;P&gt;- Decryption is working fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The combination fails because, I do not get the "block-continue-page".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any other idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 May 2014 14:54:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1083#M843</guid>
      <dc:creator>PStricker</dc:creator>
      <dc:date>2014-05-31T14:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Filter and Decryption - ERR_SSL_PROTOCOL_ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1084#M844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Phil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please take a TCP FLOW_BASIC, CTD&amp;nbsp; to get some more details information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 May 2014 16:49:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1084#M844</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-31T16:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Filter and Decryption - ERR_SSL_PROTOCOL_ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1085#M845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you please explain me what you mean with "TCP FLOW_BASIC, CTD"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 May 2014 17:22:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1085#M845</guid>
      <dc:creator>PStricker</dc:creator>
      <dc:date>2014-05-31T17:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Filter and Decryption - ERR_SSL_PROTOCOL_ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1086#M846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Phil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find below doc for the same:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1506"&gt;Packet Capture, Debug Flow-basic and Counter Commands&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jun 2014 17:10:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1086#M846</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-06-01T17:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Filter and Decryption - ERR_SSL_PROTOCOL_ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1087#M847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hulk!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is absolutely strange! Today morning, the problem has still been there and now, it is working without changing anything!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the Packet Capture, you need? How should I set the filter?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2014 05:53:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-filter-and-decryption-err-ssl-protocol-error/m-p/1087#M847</guid>
      <dc:creator>PStricker</dc:creator>
      <dc:date>2014-06-02T05:53:20Z</dc:date>
    </item>
  </channel>
</rss>

