decrypt-unsupport-param error with no decryption

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

decrypt-unsupport-param error with no decryption

Cyber Elite
Cyber Elite

We are receiving a decrypt-unsupport-param to a specific destination with no ssl inspection applied. I created a no decrypt rule and didnt apply a decryption profile so we weren't checking for expired or untrusted certs either. There is also nothing in the decryption logs for this destination IP address (we only log on failure)

 

If I filter and check the counters in the firewall I am met with TCP sessions closed via injecting RST. I can not find an indication as to why we are actually hitting an error with this site. This is a public site that we do not host.

 

In the traffic logs it shows action allow, type deny, session end reason decrypt-unsupport-param error

Claw4609_1-1687892072473.png

Claw4609_2-1687892097915.png

 

 

 

5 REPLIES 5

Community Team Member

Hi @Claw4609 ,

 

Which PAN-OS version are you currently running? I would triple-check to make sure you currently do not have any decryption policies created that could catch this traffic.

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Hello @JayGolf ,

 

We're running Pan-OS 10.2.3. To ensure it wasnt hitting a decrypt rule I placed a no decrypt decryption policy at the top with the destination of the IP address, with no decryption profile attached.

And for whatever reason the site it working today. If worked from devices outside of the network perfectly fine so the site itself was functioning fine. So no idea why it wasnt working yesterday but it is today. 

L0 Member

I too have the same issue, can anyone suggest the solutions on this.

L0 Member

We had this issue. Palo support said that the issue observed matches one of the known reports with the engineering team.

They upgraded all Prisma portals and gateway instances to the fixed version 10.2.4-h19 to resolve the issue.

  • 6075 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!