- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-28-2015 09:29 AM
Hi Friends,
how we can disable SSL V.3 only for management console on PA firewall.
Regards
Satish
01-28-2015 09:53 AM
Hello Satish,
SSL V3 option has been removed from the PAN OS 6.0.8 and 6.1.2 onward. Prior to these version, you do not have any option to disable SSL V3 on the firewall, rather, you may disable SSL-V3 on your web browser. Accordingly, the client will not send SSL-v3 during the handshake.
You may go through the security advisory for more detail information: SSL 3.0 MITM Attack (CVE-2014-3566) (PAN-SA-2014-0005) a.k.a. POODLE
Below mentioned BUG has been fixed on PAN OS 6.0.8.
71321—Removed support for SSL 3.0 from the GlobalProtect gateway, GlobalProtect portal, and Captive Portal due to CVE-2014-3566 (POODLE).
71320—Removed support for SSL 3.0 from the web interface due to CVE-2014-3566 (POODLE).
Hope this helps.
Thanks
01-28-2015 09:53 AM
Hello Satish,
SSL V3 option has been removed from the PAN OS 6.0.8 and 6.1.2 onward. Prior to these version, you do not have any option to disable SSL V3 on the firewall, rather, you may disable SSL-V3 on your web browser. Accordingly, the client will not send SSL-v3 during the handshake.
You may go through the security advisory for more detail information: SSL 3.0 MITM Attack (CVE-2014-3566) (PAN-SA-2014-0005) a.k.a. POODLE
Below mentioned BUG has been fixed on PAN OS 6.0.8.
71321—Removed support for SSL 3.0 from the GlobalProtect gateway, GlobalProtect portal, and Captive Portal due to CVE-2014-3566 (POODLE).
71320—Removed support for SSL 3.0 from the web interface due to CVE-2014-3566 (POODLE).
Hope this helps.
Thanks
01-28-2015 09:57 AM
One more related link: Palo Alto Networks Product Vulnerability - Security Advisories
Look into the SSL 3.0 MITM Attack (CVE-2014-3566)
Thanks
01-28-2015 10:53 AM
Hi Satish,
If firewall is not on the latest code, than you can not disable SSLv3.
However, there is one work around if management traffic is going through data plane. In that case through custom signature SSLv3 traffic can be blocked.
Regards,
Hardik Shah
01-28-2015 11:01 AM
Hello Hardik,
Even in latest code, we have removed the SSL v3 from the code for management connection including GlobalProtect gateway, GlobalProtect portal, and Captive Portal. There is no such option or button to enable/disable SSL V3. Secondly, if you create a custom signature to block SSL V3 connection and the client keep initiating SSL V3 connection, then you will not be able to establish a connection, which would be a major black-hole.
So, custom signature would not be a recommended solution for production environment.
Hope this helps.
Thanks
01-28-2015 05:09 PM
When will 6.1.2 be released?
01-28-2015 06:48 PM
Hello ascit,
The PAN OS version 6.1.2 is expected to be released during the week of February 2, 2015.
Thanks
01-28-2015 08:04 PM
Hi.
Thanks Hulk & Hardik for reply.
Regards
Satish
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!