Palo decrypt error unsupported

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Palo decrypt error unsupported

L4 Transporter

Hi,

 

We are receiving decrypt error in our ssl inspection traffic

 

++++As Per the below logs Server is using an unsupported EC curve x25519. Correct the server configuration to use a curve that the firewall supports.++++

2021-03-17 06:59:01.789 +0100 Error: pan_tls_ec_curve_id_2nid(pan_ec_common.c:66): unsupported ec curve_id 29<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
2021-03-17 06:59:01.789 +0100 Error: pan_ecdh_parse_server_key_exchange_msg(pan_ecdh.c:436): unsupported curve_na
me 29.<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
2021-03-17 06:59:01.789 +0100 Error: pan_ssl_keyxchg_parse_server_key_exchange_msg(pan_ssl_keyxchg.c:166): parse_
server_key_exchange_msg(ecdhe) failed<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

PAN-OS 8.1 Decryption Cipher Suites
>>https://docs.paloaltonetworks.com/compatibility-matrix/supported-cipher-suites/cipher-suites-support...

 

-------

 

 I still don't understand why the PA generates a "decryption error" instead of letting the connection go through. During testing there were some cases where the client supported TLS 1.3. As the servers also support it and the AP does not, the connection just worked. In this case, the "conflicting" information does not arrive in the "Server hello" message but just after the "key exchange" message, but since the Server hello message is not transmitted to the client, you should undo the session proxy and forward the original message from the server to the client. Anyway, I guess it can't be done for some reason.

 

any wway to solve it?

2 REPLIES 2

L7 Applicator

Hi @BigPalo 

What PAN-OS version do you use? Could you tell us the website where you see this decryption error?

L6 Presenter

If your firewall is 8.1 as you have given an article for it then you will not be able to decrypt TLS1.3. Read this:

 

 

 

https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/decryption-features/ssl-decryption...

 

 

 

Also in version 10 there is a new log for SSL decryption issues:

 

https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/troubleshoot-and-monitor-decry...

  • 2651 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!