<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need to Disable TLS 1.0 &amp;amp; 1.1 for port TCP-3978 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/346162#M86463</link>
    <description>&lt;P&gt;Hey Viveksk.Gupta,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you give me a quick hint how you set up the profile? We have the same problem and im pretty new to Palo Alto stuff, so a quick hint would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Sep 2020 05:15:55 GMT</pubDate>
    <dc:creator>thartm</dc:creator>
    <dc:date>2020-09-01T05:15:55Z</dc:date>
    <item>
      <title>Need to Disable TLS 1.0 &amp; 1.1 for port TCP-3978</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/343693#M86025</link>
      <description>&lt;P&gt;Can someone suggest on how can we disable TLS 1.0 &amp;amp; 1.1 for port TCP-3978&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Description: The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern impleme&lt;BR /&gt;ntations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used wheneve&lt;BR /&gt;r possible.&lt;BR /&gt;As of March 31, 2020, Endpoints that aren’t enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major&lt;BR /&gt;vendors.&lt;BR /&gt;PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which&lt;BR /&gt;they connect) that can be verified as not being susceptible to any known exploits.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 08:08:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/343693#M86025</guid>
      <dc:creator>viveksk.gupta</dc:creator>
      <dc:date>2020-08-13T08:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Disable TLS 1.0 &amp; 1.1 for port TCP-3978</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/343703#M86027</link>
      <description>&lt;P&gt;If you have access to the server certificate + key you can set up inbound ssl decryption and enforce 1.2 or higher through the decryption profile&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 08:30:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/343703#M86027</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-08-13T08:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Disable TLS 1.0 &amp; 1.1 for port TCP-3978</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/343704#M86028</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148872"&gt;@viveksk.gupta&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I know there is no configuration option to disable tls1.0/1.1 on this panorama management port. At least I hope that the firewalls will use tls1.2 for this connection, so if there is a firewall between the firewalls and panorama you could block tls1.0/1.1 connection attempts with a custom vulnerability signature.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 08:45:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/343704#M86028</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-13T08:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Disable TLS 1.0 &amp; 1.1 for port TCP-3978</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/344923#M86261</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cyber-Elite lia-component-message-view-widget-author-username"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592" target="_self"&gt;&lt;SPAN class="login-bold"&gt;Vsys_remo&lt;/SPAN&gt;&lt;/A&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cyber-Elite lia-component-message-view-widget-author-username"&gt;&lt;SPAN&gt;Thanks for your reply...&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cyber-Elite lia-component-message-view-widget-author-username"&gt;&lt;SPAN&gt;We have created a profile and disabled TLSv1.0 and TLSv1.1 and enabled TLSv1.2, and I have done a packet capture and I can see communication using TLSv1.2 (TAC also Confirmed TLSv1.0 disabled) but the security team able to scan TLSv1.0 and TLSv1.1 in the scan report. Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 11:41:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/344923#M86261</guid>
      <dc:creator>viveksk.gupta</dc:creator>
      <dc:date>2020-08-21T11:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Disable TLS 1.0 &amp; 1.1 for port TCP-3978</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/344924#M86262</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port TCP-3978 using for Panorama and Palo alto communication and SSL Profile have enabled TLSv1.2. Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 11:45:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/344924#M86262</guid>
      <dc:creator>viveksk.gupta</dc:creator>
      <dc:date>2020-08-21T11:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Disable TLS 1.0 &amp; 1.1 for port TCP-3978</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/346162#M86463</link>
      <description>&lt;P&gt;Hey Viveksk.Gupta,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you give me a quick hint how you set up the profile? We have the same problem and im pretty new to Palo Alto stuff, so a quick hint would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 05:15:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/346162#M86463</guid>
      <dc:creator>thartm</dc:creator>
      <dc:date>2020-09-01T05:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Disable TLS 1.0 &amp; 1.1 for port TCP-3978</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/346193#M86468</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-L0-Member lia-component-message-view-widget-author-username"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153883" target="_self"&gt;&lt;SPAN class=""&gt;Thartm,&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Login to Panorama&lt;/P&gt;&lt;P&gt;Go to &amp;gt;Panorama&amp;gt;Certificate Management&amp;gt;Certificate&amp;gt;Generate&amp;gt; (you can use existing root cert or&amp;nbsp; create new Cert)&lt;/P&gt;&lt;P&gt;Go to &amp;gt;Panorama&amp;gt;Certificate Management&amp;gt;SSL/TLS Service Profile &amp;gt;Add (call your newly created cert ) create 2 cert for Primary and secondary&lt;/P&gt;&lt;P&gt;Go to &amp;gt;Panorama&amp;gt;Setup&amp;gt;Secure Communication server call your certificate and profile both (check mark allow custom certificate only)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Verify:-&lt;/P&gt;&lt;P&gt;Go to &amp;gt;Panorama&amp;gt;managed devices&amp;gt;summary see device state must be connected and Certificate untrusted issuer&lt;/P&gt;&lt;P&gt;&amp;nbsp;Go to&amp;gt;Panorama&amp;gt;managed collectors&amp;gt;status in sync&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Please follow the document below for more information on each settings&lt;STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/panorama-web-interface/panorama-managed-collectors/log-collector-configuration/communication-settings&amp;nbsp;" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/panorama-web-interface/panorama-managed-collectors/log-collector-configuration/communication-settings&amp;nbsp;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 07:36:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/346193#M86468</guid>
      <dc:creator>viveksk.gupta</dc:creator>
      <dc:date>2020-09-01T07:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Disable TLS 1.0 &amp; 1.1 for port TCP-3978</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/346204#M86473</link>
      <description>&lt;P&gt;Thanks for the quick reply Viveksk.Gulpa &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ill look into it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 09:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/346204#M86473</guid>
      <dc:creator>thartm</dc:creator>
      <dc:date>2020-09-01T09:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Disable TLS 1.0 &amp; 1.1 for port TCP-3978</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/347322#M86622</link>
      <description>&lt;P&gt;Solution:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Login to Panorama&lt;/P&gt;&lt;P&gt;Go to &amp;gt;Panorama&amp;gt;Certificate Management&amp;gt;Certificate&amp;gt;Generate&amp;gt; (you can use existing root cert or&amp;nbsp; create new Cert)&lt;/P&gt;&lt;P&gt;Go to &amp;gt;Panorama&amp;gt;Certificate Management&amp;gt;SSL/TLS Service Profile &amp;gt;Add (call your newly created cert ) create 2 cert for Primary and secondary&lt;/P&gt;&lt;P&gt;Go to &amp;gt;Panorama&amp;gt;Setup&amp;gt;Secure Communication Settings &amp;gt;Customize Communication&amp;gt;Select HA Communication&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note:- in Palo Alto 8.X.X we can disable only TLSv1.0 we can not disable TLSv1.1 for on port-3978 TAC has confirmed to US&amp;nbsp;&lt;/P&gt;&lt;P&gt;Verify:-&lt;/P&gt;&lt;P&gt;Go to &amp;gt;Panorama&amp;gt;managed devices&amp;gt;summary see device state must be connected and Certificate untrusted issuer&lt;/P&gt;&lt;P&gt;&amp;nbsp;Go to&amp;gt;Panorama&amp;gt;managed collectors&amp;gt;status in sync&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 03:33:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-disable-tls-1-0-amp-1-1-for-port-tcp-3978/m-p/347322#M86622</guid>
      <dc:creator>viveksk.gupta</dc:creator>
      <dc:date>2020-09-08T03:33:43Z</dc:date>
    </item>
  </channel>
</rss>

