<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower Device Manager ERR_SSL_VERSION_OR_CIPHER_MISMATCH in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770942#M1039939</link>
    <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your response, and happe new year:)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is not to upload a certificate to FTD. I did that at objects management already, but this certificate isn't used by the Firepower Device Manager Webpage. It is showing me a certificate from "CN=ciscoasa" which i cannot find anywhere. Not within FTD and not in the running config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Raffael&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jan 2019 00:39:01 GMT</pubDate>
    <dc:creator>Raffael</dc:creator>
    <dc:date>2019-01-01T00:39:01Z</dc:date>
    <item>
      <title>Firepower Device Manager ERR_SSL_VERSION_OR_CIPHER_MISMATCH</title>
      <link>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770643#M1039934</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am running Firepower Threat Defense 6.2.3.7 on a ASA 5506-X at home and i recently getting these error messages when trying to connect via chrome to the Device Manager (&lt;SPAN&gt;ERR_SSL_VERSION_OR_CIPHER_MISMATCH).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I already checked via show ssl-protocol and show crypto ssl ciphers that the ciphers available are be fine. There should be several overlapping ciphers chrome could use.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Next i connected thorugh a virtual machine running Windows 7 to the device, which also got me the warning but at least i could continue configuring. I then checked the certificate offered by the site, which confused me even a bit more. The page shows me a self-signed certificate from ciscoasa. My device isnt called like this, and i cannot find this certificate in any configuration. I have imported an own certificate for the FTD but cannot find an option to tell the FTD using this certificate instead of that ciscoasa certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So maybe someone can help me here with my two questions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Why are there no ciphers overlapping? Base license is registered via smart licensing but i am not sure if that is enough&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. How can i change that certificate for Firepower Device Manager?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Raffael&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:37:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770643#M1039934</guid>
      <dc:creator>Raffael</dc:creator>
      <dc:date>2020-02-21T16:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Device Manager ERR_SSL_VERSION_OR_CIPHER_MISMATCH</title>
      <link>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770667#M1039935</link>
      <description>&lt;P&gt;I'm not sure why you are getting the cipher mismatch. I would check a packet capture to examine the SSL negotiation in detail.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as adding the external certificate, you do that in the RA VPN setup wizard as shown below. Select "Create new internal certificate" (a bit misleading) and you will be given the option to upload one:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FDM add certificate for RA VPN.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/26827i05CA3CDD739C55A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="FDM add certificate for RA VPN.PNG" alt="FDM add certificate for RA VPN.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For detailed instructions you can go to:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://&amp;lt;your FDM address&amp;gt;/#/help/t_Uploading_Internal_and_Internal_CA_Certificates.html&lt;/P&gt;</description>
      <pubDate>Mon, 31 Dec 2018 03:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770667#M1039935</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-12-31T03:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Device Manager ERR_SSL_VERSION_OR_CIPHER_MISMATCH</title>
      <link>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770693#M1039936</link>
      <description>I think the problem is in your certificate. Even if ASA/FTD has the right&lt;BR /&gt;ciphers enabled, it should be supported by the certificate public key.&lt;BR /&gt;&lt;BR /&gt;In your chrome://flags/ try to disable TLS1.3 and see if it works and make&lt;BR /&gt;sure that tls1.2 is enabled. Did you upgrade your chrome recently because I&lt;BR /&gt;heard in new versions they stopped the support for lower TLS by default.&lt;BR /&gt;</description>
      <pubDate>Mon, 31 Dec 2018 07:51:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770693#M1039936</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-12-31T07:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Device Manager ERR_SSL_VERSION_OR_CIPHER_MISMATCH</title>
      <link>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770729#M1039937</link>
      <description>&lt;P&gt;TLS 1.2 is the most commonly used in the Internet and should be supported by any browser.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using Chrome &lt;SPAN&gt;Version 71.0.3578.98&amp;nbsp;&lt;/SPAN&gt;(current latest release) and it negotiated TLS 1.2 fine with FDM on my ASA 5506-X (running FTD 6.2.3.4 and using the factory default self-signed certificate).&lt;/P&gt;</description>
      <pubDate>Mon, 31 Dec 2018 10:32:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770729#M1039937</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-12-31T10:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Device Manager ERR_SSL_VERSION_OR_CIPHER_MISMATCH</title>
      <link>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770739#M1039938</link>
      <description>Thanks Marvin for confirmation&lt;BR /&gt;</description>
      <pubDate>Mon, 31 Dec 2018 10:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770739#M1039938</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-12-31T10:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Device Manager ERR_SSL_VERSION_OR_CIPHER_MISMATCH</title>
      <link>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770942#M1039939</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your response, and happe new year:)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is not to upload a certificate to FTD. I did that at objects management already, but this certificate isn't used by the Firepower Device Manager Webpage. It is showing me a certificate from "CN=ciscoasa" which i cannot find anywhere. Not within FTD and not in the running config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Raffael&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jan 2019 00:39:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770942#M1039939</guid>
      <dc:creator>Raffael</dc:creator>
      <dc:date>2019-01-01T00:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Device Manager ERR_SSL_VERSION_OR_CIPHER_MISMATCH</title>
      <link>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770943#M1039940</link>
      <description>&lt;P&gt;Hello, and happy new year to both of you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried to disable TLS1.3 with no effect. My chrome version is&amp;nbsp;&lt;SPAN&gt;71.0.3578.98 and FTD is also up to date (maybe that is the problem). Unfortunately i didnt have time to look at that problem right when it occured the first time, so i don't know the exact time and possible causes for it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I think the certificate might be the problem, ye, but i still don't know how to change the Firepower Device Manger Web Service certificate. Any clues here.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Guess i am going to check wireshark soon.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Raffael&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jan 2019 00:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770943#M1039940</guid>
      <dc:creator>Raffael</dc:creator>
      <dc:date>2019-01-01T00:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Device Manager ERR_SSL_VERSION_OR_CIPHER_MISMATCH</title>
      <link>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770944#M1039941</link>
      <description>&lt;P&gt;Hello, and happy new year to both of you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried to disable TLS1.3 with no effect. My chrome version is&amp;nbsp;&lt;SPAN&gt;71.0.3578.98 and FTD is also up to date (maybe that is the problem). Unfortunately i didnt have time to look at that problem right when it occured the first time, so i don't know the exact time and possible causes for it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I think the certificate might be the problem, ye, but i still don't know how to change the Firepower Device Manger Web Service certificate. Any clues here.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Guess i am going to check wireshark soon.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Raffael&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jan 2019 00:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-device-manager-err-ssl-version-or-cipher-mismatch/m-p/3770944#M1039941</guid>
      <dc:creator>Raffael</dc:creator>
      <dc:date>2019-01-01T00:44:07Z</dc:date>
    </item>
  </channel>
</rss>

