Cipher suites decryption 7.1

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Cipher suites decryption 7.1

L3 Networker

Hi guys,

 

Configuring inbound SSL inspection on 7.1, decryption does not work with the newly supported cipher suites shown in the document below.

 

https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Supported-ciphers/ta-p/71969

 

Only the cipher suites shown in the document below again work. The document above states that ECDHE should work but it does not.   

 

https://live.paloaltonetworks.com/t5/Management-Articles/SSL-Decryption-Not-Working-due-to-Unsupport...

 

Could anyone provide some advice for this situation?

 

Cheers

 

4 REPLIES 4

Cyber Elite
Cyber Elite

Hi Jack

 

there are some limitations for ECDHE, did you take these into account:


   For ECDHE, only named curves.
   For ECDHE EC_point format, only uncompressed.

 

and that your cipher matches one of the listed modes (some ECDHEmodes are not supported)

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi,

 

Thanks for your response.

 

The cipher suites I'm using on the F5 load balancer are:

 

ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-CBC-SHA:ECDHE-RSA-AES128-CBC-SHA

 

Does this match the limitations for ECDHE?

 

Kind regards

Jack

Hi Jack

 

 

Those appear to match... you could try setting up a packet-diag with log features 'flow basic' and 'proxy all' for 1 single source, this may help shine some light on why it isn't working as expected

 

check out this article for some help with the packet-diag: Getting Started: Flow Basic

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Thanks for your help!

 

Turns out in the small print the EDHC ciphers are only supported in SSL forward proxy decryption, not inbound, which is why they don't work with the current setup. So, although Palo state that certain ciphers are now supported in 7.1, it's best not to just go by the new cipher suites added in 7.1.

 

It's in very small print in the Decryption Profile under Protocol Settings:

 

protocol settings.png

 

Anyway, thank you again for your help. 

 

 

 

Thanks

Jack

  • 2421 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!