<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Decryption on FTD appliances not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4195237#M1076513</link>
    <description>&lt;P&gt;I have this same exact issue, did you ever figure out a fix? We do not allow 443 UDP by default however as you mention the traffic in the connection events is showing 443TCP and a status of 'Do Not Decrypt (Uncached Session)'.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Dec 2020 15:22:46 GMT</pubDate>
    <dc:creator>JohnDenver2135</dc:creator>
    <dc:date>2020-12-08T15:22:46Z</dc:date>
    <item>
      <title>SSL Decryption on FTD appliances not working</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4132166#M1072728</link>
      <description>&lt;P&gt;My SSL decryption policy is working but the FTDs are experiencing issues trying to decrypt sites that appear to be protected by cloudflare. For example, if I go to yahoo.com, I can see the certificate in my browser was intercepted by the FTD and the FTD is decrypt-resigning the traffic (via event viewer). However if I go to pcpartpicker.com, and look at the certificate, I can see that the FTD did not decrypt-resign as expected. When looking at the certificate via my browser it says issued by CloudFlare Inc (not my FTD). Another thing to note is that my connection in the browser shows a quick reset before actually loading the page. Does anyone else experience this behavior? I tested this across multiple FTDs 5508-X and FP2110 running 6.4.x and 6.6.0.1. Same behavior. Even with multiple browsers.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 18:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4132166#M1072728</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-08-07T18:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption on FTD appliances not working</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4132170#M1072731</link>
      <description>&lt;P&gt;Could it be the problem connections are using quic (udp/443) and not classic https (tcp/443)?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 18:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4132170#M1072731</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-08-07T18:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption on FTD appliances not working</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4132199#M1072735</link>
      <description>&lt;P&gt;The connection event shows tcp/443. What is interesting is ssl status is 'Do Not Decrypt (Uncached Session)'.&amp;nbsp; Not sure what that means.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 20:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4132199#M1072735</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-08-07T20:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption on FTD appliances not working</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4195237#M1076513</link>
      <description>&lt;P&gt;I have this same exact issue, did you ever figure out a fix? We do not allow 443 UDP by default however as you mention the traffic in the connection events is showing 443TCP and a status of 'Do Not Decrypt (Uncached Session)'.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 15:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4195237#M1076513</guid>
      <dc:creator>JohnDenver2135</dc:creator>
      <dc:date>2020-12-08T15:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption on FTD appliances not working</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4195300#M1076516</link>
      <description>&lt;P&gt;I upgraded to 6.6.1, ran into bug&amp;nbsp;CSCvs99356.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upgraded to 6.7 and hit a new issue where I get&amp;nbsp;&lt;SPAN&gt;NET::ERR_CERT_AUTHORITY_INVALID when loading a new webpage. If I hit refresh or F5, the page then does load correctly, without any certificate error. Sites protected by cloudfare seem to now be decrypted&amp;nbsp;by FTD, before in 6.4 they were not. I have pending TAC case for this new issue. I cannot reproduce this new issue in 6.4 or 6.6.1 across&amp;nbsp;multiple sites with computers on the same domain and use the same SSL policy. Issuing a new certificate for decrypt policy has the same issue. I would be curious to know if someone else has this issue which I have opened a new thread on.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 16:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4195300#M1076516</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-12-08T16:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption on FTD appliances not working</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4309167#M1079377</link>
      <description>&lt;P&gt;This seems to be fixed in 6.6.3 now. I was seeing similar issues in 6.6.1. Hoping to upgrade soon.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 19:39:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4309167#M1079377</guid>
      <dc:creator>jonathankarras</dc:creator>
      <dc:date>2021-03-17T19:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption on FTD appliances not working</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4309241#M1079383</link>
      <description>&lt;P&gt;Sigh, hopefully next release of 6.7 is out soon for this fix.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 21:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4309241#M1079383</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2021-03-17T21:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Decryption on FTD appliances not working</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4437307#M1082420</link>
      <description>&lt;P&gt;In case anyone is wondering, this magically started to work when upgrading to version 7, with no changes on our end.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 13:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-on-ftd-appliances-not-working/m-p/4437307#M1082420</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2021-07-22T13:10:08Z</dc:date>
    </item>
  </channel>
</rss>

