Cipher suites decryption 7.1

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cipher suites decryption 7.1

L3 Networker

Hi guys,


Configuring inbound SSL inspection on 7.1, decryption does not work with the newly supported cipher suites shown in the document below.


Only the cipher suites shown in the document below again work. The document above states that ECDHE should work but it does not.


Could anyone provide some advice for this situation?





Cyber Elite
Cyber Elite

Hi Jack


there are some limitations for ECDHE, did you take these into account:

   For ECDHE, only named curves.
   For ECDHE EC_point format, only uncompressed.


and that your cipher matches one of the listed modes (some ECDHEmodes are not supported)

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy



Thanks for your response.


The cipher suites I'm using on the F5 load balancer are:




Does this match the limitations for ECDHE?


Kind regards


Hi Jack



Those appear to match... you could try setting up a packet-diag with log features 'flow basic' and 'proxy all' for 1 single source, this may help shine some light on why it isn't working as expected


check out this article for some help with the packet-diag: Getting Started: Flow Basic

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy

Thanks for your help!


Turns out in the small print the EDHC ciphers are only supported in SSL forward proxy decryption, not inbound, which is why they don't work with the current setup. So, although Palo state that certain ciphers are now supported in 7.1, it's best not to just go by the new cipher suites added in 7.1.


It's in very small print in the Decryption Profile under Protocol Settings:


protocol settings.png


Anyway, thank you again for your help. 






Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!