Since update to 3.1.4 no ssl decryption

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Since update to 3.1.4 no ssl decryption

L3 Networker

We have some user categories with "no decryption" but the default rule "decrypt".

Before updating from 3.1.3, https://secure.eicar.org/eicar.com.txt was blocked reliably. Since 3.1.4 not. Nothing else was changed.

In fact i cannot see any ssl decryption on my PAN 2050. Is there a way to troubleshoot the issue?

4 REPLIES 4

L3 Networker

please contact your support provider and open up a case via email or phone call.

L3 Networker

The PA2050 shows:

CLI: show system setting ssl-decrypt certificate-cache | match Cached
Cached 252 certificates

CLI: debug dataplane reset ssl-decrypt certificate-cache

deleted 252 cert entries
has resolved the problem.

This is a known issue in 3.1.4 and 3.1.5.


Unfortunately, as you can understand it is not possible to execute this command in order to temporarily resolve the problem.

The issue also existis as well in the updated version 3.1.6.

These versions 3.1.4, 3.1.5 and 3.1.6 have several issues with SSL Decryption that stops working. A case has been opened and we are waiting for the next software update (3.1.7?) to resolve all the ssl-decryption issues.

Regards,

George

SSL Decryption issues seem to have been resolved in 3.1.7

  • 2740 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!