disable SSL V.3

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

disable SSL V.3

L4 Transporter

Hi Friends,

how we can disable SSL V.3  only for management console on PA firewall.


Regards

Satish

1 accepted solution

Accepted Solutions

L7 Applicator

Hello Satish, Smiley Happy

SSL V3 option has been removed from the PAN OS 6.0.8 and 6.1.2 onward. Prior to these version, you do not have any option to disable SSL V3 on the firewall, rather, you may disable SSL-V3 on your web browser. Accordingly, the client will not send SSL-v3 during the handshake.

You may go through the security advisory for more detail information: SSL 3.0 MITM Attack (CVE-2014-3566) (PAN-SA-2014-0005) a.k.a. POODLE

Below mentioned BUG has been fixed on PAN OS 6.0.8.

71321—Removed support for SSL 3.0 from the GlobalProtect gateway, GlobalProtect portal, and Captive Portal due to CVE-2014-3566 (POODLE).

71320—Removed support for SSL 3.0 from the web interface due to CVE-2014-3566 (POODLE).

Hope this helps.

Thanks

View solution in original post

7 REPLIES 7

L7 Applicator

Hello Satish, Smiley Happy

SSL V3 option has been removed from the PAN OS 6.0.8 and 6.1.2 onward. Prior to these version, you do not have any option to disable SSL V3 on the firewall, rather, you may disable SSL-V3 on your web browser. Accordingly, the client will not send SSL-v3 during the handshake.

You may go through the security advisory for more detail information: SSL 3.0 MITM Attack (CVE-2014-3566) (PAN-SA-2014-0005) a.k.a. POODLE

Below mentioned BUG has been fixed on PAN OS 6.0.8.

71321—Removed support for SSL 3.0 from the GlobalProtect gateway, GlobalProtect portal, and Captive Portal due to CVE-2014-3566 (POODLE).

71320—Removed support for SSL 3.0 from the web interface due to CVE-2014-3566 (POODLE).

Hope this helps.

Thanks

L7 Applicator

One more related link: Palo Alto Networks Product Vulnerability - Security Advisories

Look into the SSL 3.0 MITM Attack (CVE-2014-3566)

Thanks

L6 Presenter

Hi Satish,

If firewall is not on the latest code, than you can not disable SSLv3.

However, there is one work around if management traffic is going through data plane. In that case through custom signature SSLv3 traffic can be blocked.

Regards,

Hardik Shah

Hello Hardik,

Even in latest code, we have removed the SSL v3 from the code for management connection including GlobalProtect gateway, GlobalProtect portal, and Captive Portal. There is no such option or button to enable/disable SSL V3. Secondly, if you create a custom signature to block SSL V3 connection and the client keep initiating SSL V3 connection,  then you will not be able to establish a connection, which would be a major black-hole.

So, custom signature would not be a recommended solution for production environment.

Hope this helps.

Thanks

When will 6.1.2 be released?

Hello ascit,

The PAN OS version 6.1.2 is expected to be released during the week of February 2, 2015.

Thanks

L4 Transporter

Hi.

Thanks Hulk & Hardik for reply.Smiley Happy



Regards

Satish

  • 1 accepted solution
  • 4788 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!