SSL Version

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

SSL Version

L5 Sessionator

Is there any way for the traffic logs to display the SSL/TLS version that's in use for a particular flow? I don't see the data in the traffic logs or in the session info at the CLI.

4 REPLIES 4

Cyber Elite
Cyber Elite

@rmfalconer,

This information is written to any log file; if it's a desired feature I would raise the request with your SE. 

So the info is written to a log file and it just needs to be exposed so that it can be viewed? Or it's not written to any log file and a request should be submitted to an SE for this info to be captured?

That information is not written to a log file, as far as I know.

 

As a workaround, you may be able to define custom applications that identify the different versions from header information, and report on the use of those...

I like the workaround described by @JoeAndreini, but if you do that there are some things that you need to pay attention to:

  • If you do TLS decryption then make sure that you activate the checkbox in the custom app for continue scanning for other apps. Otherwise you will loose a big part of the visibility that paloalto provides. But at the same time you need to enable session start logs because you will not see the custom app in the logs.
  • If you don't decrypt traffic then you don't need to enable the checlbox to scan for other apps but at least a small part of the visibility will also go away.
  • 2680 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!