SSL Version

Reply
L4 Transporter

SSL Version

Is there any way for the traffic logs to display the SSL/TLS version that's in use for a particular flow? I don't see the data in the traffic logs or in the session info at the CLI.

L7 Applicator

Re: SSL Version

@rmfalconer,

This information is written to any log file; if it's a desired feature I would raise the request with your SE. 

L4 Transporter

Re: SSL Version

So the info is written to a log file and it just needs to be exposed so that it can be viewed? Or it's not written to any log file and a request should be submitted to an SE for this info to be captured?

L4 Transporter

Re: SSL Version

That information is not written to a log file, as far as I know.

 

As a workaround, you may be able to define custom applications that identify the different versions from header information, and report on the use of those...

L7 Applicator

Re: SSL Version

I like the workaround described by @JoeAndreini, but if you do that there are some things that you need to pay attention to:

  • If you do TLS decryption then make sure that you activate the checkbox in the custom app for continue scanning for other apps. Otherwise you will loose a big part of the visibility that paloalto provides. But at the same time you need to enable session start logs because you will not see the custom app in the logs.
  • If you don't decrypt traffic then you don't need to enable the checlbox to scan for other apps but at least a small part of the visibility will also go away.
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!