SSL Inbound // decrypt-unsuppot-pram

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

SSL Inbound // decrypt-unsuppot-pram

L4 Transporter

What can i do here..Is it something we have to fix on server side or firewall.

 

Not Working, Block sessions with unsupported cipher suites, Selected.

Protocols allowed min SSL3.0 to MAX

raji_toor_1-1593023342068.png

 

 

Working, with Block sessions with unsupported cipher suites, Un-selected.

raji_toor_0-1593023022338.png

 

NMAP scan of server

 
3 REPLIES 3

L4 Transporter

NMAP Scan for server

raji_toor_0-1593023870449.png

 

@raji_toor,

Was this ever working before or is this the first time you are attempting to decrypt this traffic? Setting up inbound decryption on the PFS ciphers is a bit different then it was previously because the firewall actually needs to proxy the connection instead of just decrypting the traffic in-line like it can with older ciphers.

Also just glancing at your cipher list you have a few being offered that the firewalls doesn't actively support. You'll want to check the available ciphers for your software release as this changes between most major releases and ensure that the firewall supports each being offered. 

@BPry Yes this is my first attempt at inbound decryption, i do have outbound working for few months now.

 

On comparison for what is supported for 9.0 and what the nmap shows me, i see quite few are common between them.

raji_toor_0-1593098796516.png

After enabling inbound inspection namp sees only 2, profile setting for now allows 3.0 to 1.2

raji_toor_1-1593098915710.png

So how do i proxy the connection, the only to configure is see is to have the cert on firewall, create decryption profile and attach to decryption policy. Policy/Profile don't seem to provide any option for proxy.

 

  • 2456 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!