<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD: SSL Error accessing management page from internal interface. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-ssl-error-accessing-management-page-from-internal-interface/m-p/4401571#M1080705</link>
    <description>&lt;P&gt;I just installed a new FTD in Azure (standalone, not managed by FMC), running 6.7.0-65.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I so far we have done no config, just set set a single static route to access our VNET and enabled management over the inside data interface. Getting a&amp;nbsp;&lt;SPAN&gt;ERR_SSL_VERSION_OR_CIPHER_MISMATCH error accessing over the Inside Interface IP address, but works fine via the Management&amp;nbsp;Interface.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I did a packet inspection with Wireshark and can see that via Management&amp;nbsp;Int TLS 1.2 is negotiated, but over the Inside Interface it tries and fails to negotiate TLS 1.0 (which I assume Cisco has disabled for security reasons). I have no idea why 1.0 is being attempted, I even tried disabling it on my browser, but get the same result.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Again, all other settings on the FTDv are set at default for version 6.7. Taking a guess that maybe some kind of SSL inspection might be causing the issue, but haven't found what I need to disable, or what rule I need to create to allow (assuming that is even the issue).&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 May 2021 01:50:17 GMT</pubDate>
    <dc:creator>sphbecker1</dc:creator>
    <dc:date>2021-05-12T01:50:17Z</dc:date>
    <item>
      <title>FTD: SSL Error accessing management page from internal interface.</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ssl-error-accessing-management-page-from-internal-interface/m-p/4401571#M1080705</link>
      <description>&lt;P&gt;I just installed a new FTD in Azure (standalone, not managed by FMC), running 6.7.0-65.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I so far we have done no config, just set set a single static route to access our VNET and enabled management over the inside data interface. Getting a&amp;nbsp;&lt;SPAN&gt;ERR_SSL_VERSION_OR_CIPHER_MISMATCH error accessing over the Inside Interface IP address, but works fine via the Management&amp;nbsp;Interface.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I did a packet inspection with Wireshark and can see that via Management&amp;nbsp;Int TLS 1.2 is negotiated, but over the Inside Interface it tries and fails to negotiate TLS 1.0 (which I assume Cisco has disabled for security reasons). I have no idea why 1.0 is being attempted, I even tried disabling it on my browser, but get the same result.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Again, all other settings on the FTDv are set at default for version 6.7. Taking a guess that maybe some kind of SSL inspection might be causing the issue, but haven't found what I need to disable, or what rule I need to create to allow (assuming that is even the issue).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 01:50:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ssl-error-accessing-management-page-from-internal-interface/m-p/4401571#M1080705</guid>
      <dc:creator>sphbecker1</dc:creator>
      <dc:date>2021-05-12T01:50:17Z</dc:date>
    </item>
  </channel>
</rss>

