<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL inbound inspection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344745#M86230</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I analyze the packet capture and found below:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 - Paloalto only support limited Elliptic curves which are received by server hello:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1597909856483.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27444i96C1F28C4AB0CC5C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1597909856483.png" alt="Jafar_Hussain_0-1597909856483.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;bu in this packet capture i am not able to find any Elliptic curve detail.&lt;/P&gt;&lt;P&gt;Supported elliptic details are below:-&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;P-192 (secp192r1)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;P-224 (secp224r1)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;P-256 (secp256r1)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;P-384 (secp384r1)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;P-521 (secp521r1)&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/supported-cipher-suites/cipher-suites-supported-in-pan-os-8-1/cipher-suites-supported-in-pan-os-8-1-decryption" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/supported-cipher-suites/cipher-suites-supported-in-pan-os-8-1/cipher-suites-supported-in-pan-os-8-1-decryption&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;2 - I have gone through the below documents and found the extension: extended_master_secret is same for client and server hello.&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://smartnets.wordpress.com/2016/11/07/palo-alto-firewalls-unable-to-decrypt-ssl-inbound-traffic/" target="_blank" rel="noopener"&gt;https://smartnets.wordpress.com/2016/11/07/palo-alto-firewalls-unable-to-decrypt-ssl-inbound-traffic/&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;But i am not sure what is the reason i am getting decryption error intermittently.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 20 Aug 2020 07:54:42 GMT</pubDate>
    <dc:creator>Jafar_Hussain</dc:creator>
    <dc:date>2020-08-20T07:54:42Z</dc:date>
    <item>
      <title>SSL inbound inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344625#M86213</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I am facing the issue in SSL decryption intermittently. For the transaction website.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;traffic flow for the SSL inspection is:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Outside user ------&amp;gt; Paloalto---------&amp;gt;Load balancer--------&amp;gt;Application server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the destination NAT translation, i have given the load balancer IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Condition A with SSL inspection&lt;/U&gt;:-&lt;/P&gt;&lt;P&gt;Once we apply SSL inspection we can see the application webpage is open properly but some time transfer page was showing blank.&lt;/P&gt;&lt;P&gt;We tried to do transactions multiple times and it was successful sometimes and sometimes stuck on-page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Condition B without SSL inspection&lt;/U&gt;:-&lt;/P&gt;&lt;P&gt;Everything is working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Troubleshooting:-&lt;/P&gt;&lt;P&gt;Below is the counter value:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ssl.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27439i4D2A9B4A9E72DC0C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ssl.PNG" alt="ssl.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;I just found this error in counter but not able to understand what is the exact issue.&lt;/P&gt;&lt;P&gt;Could you please give me any sugesion in this.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 19:57:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344625#M86213</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-08-19T19:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344635#M86214</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;What session_end_reason were you getting on the sessions that were giving an error? On your decryption profile, what options if any do you have checked under SSL Inbound Inspection?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 20:14:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344635#M86214</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-08-19T20:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344642#M86215</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i login in website page the decryption showing traffic is decrypted. after login once i click any functionality like transaction the traffic is showing decrypt-error.&lt;/P&gt;&lt;P&gt;didn't apply any decryption profile, it is none.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 20:19:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344642#M86215</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-08-19T20:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344745#M86230</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I analyze the packet capture and found below:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 - Paloalto only support limited Elliptic curves which are received by server hello:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1597909856483.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27444i96C1F28C4AB0CC5C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1597909856483.png" alt="Jafar_Hussain_0-1597909856483.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;bu in this packet capture i am not able to find any Elliptic curve detail.&lt;/P&gt;&lt;P&gt;Supported elliptic details are below:-&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;P-192 (secp192r1)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;P-224 (secp224r1)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;P-256 (secp256r1)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;P-384 (secp384r1)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;P-521 (secp521r1)&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/supported-cipher-suites/cipher-suites-supported-in-pan-os-8-1/cipher-suites-supported-in-pan-os-8-1-decryption" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/supported-cipher-suites/cipher-suites-supported-in-pan-os-8-1/cipher-suites-supported-in-pan-os-8-1-decryption&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;2 - I have gone through the below documents and found the extension: extended_master_secret is same for client and server hello.&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://smartnets.wordpress.com/2016/11/07/palo-alto-firewalls-unable-to-decrypt-ssl-inbound-traffic/" target="_blank" rel="noopener"&gt;https://smartnets.wordpress.com/2016/11/07/palo-alto-firewalls-unable-to-decrypt-ssl-inbound-traffic/&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;But i am not sure what is the reason i am getting decryption error intermittently.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 20 Aug 2020 07:54:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344745#M86230</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-08-20T07:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inbound inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344761#M86233</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to add one more point, i have analyzed the counter again and found the below value:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;Number of ssl sessions can't be decrypted because of out of resources proxy_l2hdr_extended 13 1 info proxy pktpro&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;apart from this 9 other SSL inbound policy is working perfectly.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 10:48:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-inbound-inspection/m-p/344761#M86233</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-08-20T10:48:01Z</dc:date>
    </item>
  </channel>
</rss>

