<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Do we have any more in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751219#M6020</link>
    <description>&lt;P&gt;Do we have any more indications when "SOON" will be? More and more sites are moving to TLS 1.1 / 1.2 and becoming inaccessible unless we bypass them (which opens us up to potential malware infection if the site becomes compromised.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm honestly at a total loss how Cisco still doesn't support these protocols, which have been in use for YEARS.&amp;nbsp; TLS 1.1 in &lt;STRONG&gt;&lt;U&gt;2006 &lt;/U&gt;&lt;/STRONG&gt;and TLS 1.2 in &lt;STRONG&gt;&lt;U&gt;2008 &lt;/U&gt;&lt;/STRONG&gt;!!&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2015 13:39:48 GMT</pubDate>
    <dc:creator>ashaw216</dc:creator>
    <dc:date>2015-09-30T13:39:48Z</dc:date>
    <item>
      <title>HTTPS site fails to load</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751217#M6018</link>
      <description>&lt;P&gt;There are several HTTPS sites which, when we try to access them, give varying errors (Firefox "Secure Connection Failed", IE "Turn on TLS 1.0, TLS 1.1, and TLS 1.2 in Advanced settings and try connecting..." even though these are turned on, and Chrome "The webpage is not available ERR_CONNECTION_CLOSED").&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Within the proxylog on the WSA170 I see these lines:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Warning: HTTPS : - : Unknown algorithm for public key in X509 certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I run an SSL test against the site it says it supports TLS 1.0 - 1.2, but not SSL. I'm wondering why we're not able to connect.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2015 17:28:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751217#M6018</guid>
      <dc:creator>ashaw216</dc:creator>
      <dc:date>2015-08-12T17:28:15Z</dc:date>
    </item>
    <item>
      <title>There are a couple of things</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751218#M6019</link>
      <description>&lt;P&gt;There are a couple of things that could be going on:&lt;/P&gt;&lt;P&gt;1. The current WSA versions don't support TLS 1.1 or 1.2.&amp;nbsp; TLS1.1/1.2 support is coming SOON.&lt;/P&gt;&lt;P&gt;2. there's a bug related to how the WSA tries to negotiate this, it&amp;nbsp;will show up in the access logs as 502 errors for the site in question.&amp;nbsp; The fix for this is coming soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ended up creating a custom category, setting it to "Pass-through" in the Decryption Access Policies"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2015 17:43:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751218#M6019</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2015-08-12T17:43:30Z</dc:date>
    </item>
    <item>
      <title>Do we have any more</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751219#M6020</link>
      <description>&lt;P&gt;Do we have any more indications when "SOON" will be? More and more sites are moving to TLS 1.1 / 1.2 and becoming inaccessible unless we bypass them (which opens us up to potential malware infection if the site becomes compromised.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm honestly at a total loss how Cisco still doesn't support these protocols, which have been in use for YEARS.&amp;nbsp; TLS 1.1 in &lt;STRONG&gt;&lt;U&gt;2006 &lt;/U&gt;&lt;/STRONG&gt;and TLS 1.2 in &lt;STRONG&gt;&lt;U&gt;2008 &lt;/U&gt;&lt;/STRONG&gt;!!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 13:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751219#M6020</guid>
      <dc:creator>ashaw216</dc:creator>
      <dc:date>2015-09-30T13:39:48Z</dc:date>
    </item>
    <item>
      <title>I was in the beta, it exited</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751220#M6021</link>
      <description>&lt;P&gt;I was in the beta, it exited a few weeks ago...I expect that FCS is imminent but don't&amp;nbsp;have dates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And yes Product Management knows they dropped the ball big time on this one...&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 14:04:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751220#M6021</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2015-09-30T14:04:00Z</dc:date>
    </item>
    <item>
      <title>Looking forward to the latest</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751221#M6022</link>
      <description>&lt;P&gt;Looking forward to the latest update. We are having a lot more issues with this lately.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 14:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751221#M6022</guid>
      <dc:creator>Paul Cardelli</dc:creator>
      <dc:date>2015-09-30T14:20:48Z</dc:date>
    </item>
    <item>
      <title>Good Morning Thanks for</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751222#M6023</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Good Morning &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Thanks for reaching out, Support for TLS 1.1 / 1.2 is available with the version 9.0.0-485 build (currently is limited deployment) provisioned based.&amp;nbsp; Please create a TAC case with the serial number of the Appliance needed to have this version provisioned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Zack&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 15:00:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751222#M6023</guid>
      <dc:creator>Atazazuddin Shaikh</dc:creator>
      <dc:date>2015-09-30T15:00:19Z</dc:date>
    </item>
    <item>
      <title>I currently have a TAC case</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751223#M6024</link>
      <description>&lt;P&gt;I currently have a TAC case open for our S680s. &amp;nbsp;Should the engineer be able to provision this version for us? &amp;nbsp;Having several incredibly frustrating issues including this.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 01:44:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751223#M6024</guid>
      <dc:creator>blroberts2</dc:creator>
      <dc:date>2015-10-02T01:44:01Z</dc:date>
    </item>
    <item>
      <title>Good Morning  That is correct</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751224#M6025</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Good Morning &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;That is correct, Please let your TAC engineer know and he/she will be able to have it provisioned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Zack&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 12:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751224#M6025</guid>
      <dc:creator>Atazazuddin Shaikh</dc:creator>
      <dc:date>2015-10-02T12:56:37Z</dc:date>
    </item>
    <item>
      <title>Our account manager has</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751225#M6026</link>
      <description>&lt;P&gt;Our account manager has mentioned that this update may require a memory upgrade of the appliance (!) -- what are the requirements for it?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 13:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751225#M6026</guid>
      <dc:creator>ashaw216</dc:creator>
      <dc:date>2015-10-02T13:07:53Z</dc:date>
    </item>
    <item>
      <title>Their are some memory</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751226#M6027</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Their are some memory requirement for S370 (MUST be 8 Gig RAM),&amp;nbsp; Please have TAC engineer do the research for you and address all the concerns / questions you may have.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Zack&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 18:18:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751226#M6027</guid>
      <dc:creator>Atazazuddin Shaikh</dc:creator>
      <dc:date>2015-10-02T18:18:31Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751227#M6028</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I'd like to say we got 9.0.0-485 (S380) and our users can't access to &lt;A href="https://www.ingdirect.es" target="_blank"&gt;https://www.ingdirect.es&lt;/A&gt;. In the browser we get ERR_CONNECTION_CLOSED. I downloaded pcap from our firewall and can see WSA sends to the remote server this:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;TLSv1.2 Record Alert (Level: Fatal, Description: Unsupported Extension)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;After it WSA sends a RST to ingdirect server.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I thought this problem was fixed in 9.0.0-485.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 12:10:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751227#M6028</guid>
      <dc:creator>francisco del cura ferreira</dc:creator>
      <dc:date>2016-02-23T12:10:57Z</dc:date>
    </item>
    <item>
      <title>The site https://www</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751228#M6029</link>
      <description>&lt;P&gt;The site&amp;nbsp;&lt;SPAN&gt;https://www.ingdirect.es loads fine for me, running&amp;nbsp;9.0.1-162.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 12:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751228#M6029</guid>
      <dc:creator>Erik Dahle</dc:creator>
      <dc:date>2016-02-24T12:37:21Z</dc:date>
    </item>
    <item>
      <title>Hi Erik</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751229#M6030</link>
      <description>&lt;P&gt;Hi Erik&lt;/P&gt;
&lt;P&gt;I read in another thread 9.0.0-485 didn't fix the TLS v1.2 issue. We have to schedule an upgrade to 9.0.1-162, I'm sure the issue will be fixed after upgrading.&lt;/P&gt;
&lt;P&gt;Thanks for answering.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 12:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751229#M6030</guid>
      <dc:creator>francisco del cura ferreira</dc:creator>
      <dc:date>2016-02-24T12:41:11Z</dc:date>
    </item>
    <item>
      <title>Problem solved:  we switched</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751230#M6031</link>
      <description>&lt;P&gt;Problem solved:&amp;nbsp; we switched to Websense (now Forcepoint), which doesn't have this issue.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 11:23:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751230#M6031</guid>
      <dc:creator>ashaw216</dc:creator>
      <dc:date>2016-04-13T11:23:06Z</dc:date>
    </item>
    <item>
      <title>Good morning,</title>
      <link>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751231#M6032</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;
&lt;P&gt;To me it happens the same for the website &lt;A href="https://esta.cbp.dhs.gov/" target="_blank"&gt;https://esta.cbp.dhs.gov/&lt;/A&gt; I generate the error ERR_CONNECTION_CLOSED from the browser, in the capture of logs from the WSA I get error code 502:&lt;/P&gt;
&lt;P&gt;1483558564.689 968 10.10.165.35 TCP_MISS / 502 0 TCP_CONNECT 216.81.87.20:443 - DIRECT / esta.cbp.dhs.gov - PASSTHRU_WEBCAT_7-INTERNETVIP-RedWifiRed0-NONE-NONE-NONE-DefaultGroup &amp;lt;IW_gov, 3.9, -, "-", IW_gov, -, "-", "-", "-", "-", "-", "-" "-" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" ""&lt;/P&gt;
&lt;P&gt;This happens to the version of WSA 9.1.1-074, but in a WSA with version 8.5.2-027 I do not happen this type of error; Please can you inform me the root cause of this behavior and how can I solve it. Thank you in advance for your cooperation.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 19:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-site-fails-to-load/m-p/2751231#M6032</guid>
      <dc:creator>soporte.redes2</dc:creator>
      <dc:date>2017-01-05T19:57:15Z</dc:date>
    </item>
  </channel>
</rss>

