<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD: When exactly &amp;quot;VPN Decrypt&amp;quot; (not SSL decrypt) happens in FTD traffic flow? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413641#M1081323</link>
    <description>&lt;P&gt;Hello HQuest,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply. Appreciate it. But still my original question remains; how you can examine the inner packet for 'existing connections' without decrypting the tunneled traffic first. I believe that the 'existing connections' we are referring to is for the inner IP connections and not on the IPSec tunnel headers. Right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mohan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 06 Jun 2021 14:02:34 GMT</pubDate>
    <dc:creator>muthumohan</dc:creator>
    <dc:date>2021-06-06T14:02:34Z</dc:date>
    <item>
      <title>FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413445#M1081310</link>
      <description>&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Its been bothering me for a while now. The flow charts on all Cisco documents show that 'VPN Decrypt' happens after checking for 'Existing Connections'. (see attached flow chart).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;My question is, how will FTD know whether the connection is existing or not, even before decrypting the VPN traffic? Here I believe the 'existing connections' refers to the inner IP traffic and not to the outer IPSec header. Shouldn't VPN decrypt happen first, so that the inner IP traffic can be checked for 'existing connections'? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;What am I missing?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Thank you in advance.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jun 2021 14:59:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413445#M1081310</guid>
      <dc:creator>muthumohan</dc:creator>
      <dc:date>2021-06-05T14:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413508#M1081313</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="212321-clarify-the-firepower-threat-defense-acc-03.png copy.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121925i884A334777243DD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="212321-clarify-the-firepower-threat-defense-acc-03.png copy.png" alt="212321-clarify-the-firepower-threat-defense-acc-03.png copy.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jun 2021 22:16:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413508#M1081313</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-06-05T22:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413544#M1081315</link>
      <description>&lt;P&gt;I thought the FastPath pre-filter policy bypassed DAQ entirely... ain't that the case any more?&lt;/P&gt;&lt;P&gt;From&amp;nbsp;the Configuration and Operation of FTD Prefilter Policies (&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212700-configuration-and-operation-of-ftd-prefi.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212700-configuration-and-operation-of-ftd-prefi.html&lt;/A&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;A Prefilter Policy is a feature introduced in 6.1 version and serves three main purposes:&lt;/P&gt;&lt;P&gt;* Match traffic based on both inner and outer headers&lt;BR /&gt;* &lt;STRONG&gt;Provide early Access Control which allows a flow to bypass Snort engine completely&lt;/STRONG&gt;&lt;BR /&gt;* Work as a placeholder for&amp;nbsp;Access Control Entries (ACEs) that are migrated from&amp;nbsp;Adaptive Security Appliance (ASA) migration tool.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 02:52:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413544#M1081315</guid>
      <dc:creator>HQuest</dc:creator>
      <dc:date>2021-06-06T02:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413550#M1081316</link>
      <description>&lt;P&gt;That picture was inaccurate with regard to the Fastpath and prefilter indications. This one from a Cisco Live presentation is a better reference: (&lt;STRONG&gt;UPDATE&lt;/STRONG&gt; - please refer to the better diagram in my later reply.)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTD Order of Operations" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121929i5736719940E5FBCB/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTD OOO reference.PNG" alt="FTD Order of Operations" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;FTD Order of Operations&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 15:01:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413550#M1081316</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-06T15:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413592#M1081318</link>
      <description>&lt;P&gt;Even yours doesn’t feel right. The Fastpath connection should only bypass the DAQ and nothing else. ALG checks and NAT are applied on Fastpath data - you can confirm with a packet tracer on a Prefilter policy.&lt;/P&gt;&lt;P&gt;It is worrisome even Cisco Live presenters are not fully understanding the product…&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 10:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413592#M1081318</guid>
      <dc:creator>HQuest</dc:creator>
      <dc:date>2021-06-06T10:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413599#M1081319</link>
      <description>&lt;P&gt;I read the check for an existing connection as for the external layer.&lt;/P&gt;&lt;P&gt;The payload decryption should happen after an external new connection was identified as a tunnel. Meaning the FTD device is aware a connection exists, it found an internal session, it tagged it as a tunnel and it has to be decrypted (see Policies / Prefilter). You cannot start with the decryption right away, as you were just provided with the packet and you have no tracking of it. Also you don’t know yet if that header/payload is of a tunnel nor what the Prefilter is calling - perhaps it should not be and you just wasted resources. Unless they are doing something pretty funny on the device internals, to the point they won’t even document what or why.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 10:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413599#M1081319</guid>
      <dc:creator>HQuest</dc:creator>
      <dc:date>2021-06-06T10:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413641#M1081323</link>
      <description>&lt;P&gt;Hello HQuest,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply. Appreciate it. But still my original question remains; how you can examine the inner packet for 'existing connections' without decrypting the tunneled traffic first. I believe that the 'existing connections' we are referring to is for the inner IP connections and not on the IPSec tunnel headers. Right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mohan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 14:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413641#M1081323</guid>
      <dc:creator>muthumohan</dc:creator>
      <dc:date>2021-06-06T14:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413650#M1081324</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ffff.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121952i096179B497958B04/image-size/large?v=v2&amp;amp;px=999" role="button" title="ffff.png" alt="ffff.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 14:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413650#M1081324</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-06-06T14:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413652#M1081325</link>
      <description>&lt;P&gt;thanks A lot friend,&amp;nbsp;&lt;BR /&gt;can you share the name of ciscolive PPT?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 14:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413652#M1081325</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-06-06T14:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413661#M1081326</link>
      <description>&lt;P&gt;I found an even better (and I believe more accurate) depiction - see below.Credit to Nazmul Rajib - it is from his book "Cisco Firepower Threat Defense" (Chapter 16). (I hope you don't mind me citing it &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/339519"&gt;@Nazmul Rajib&lt;/a&gt;)&lt;/P&gt;
&lt;P&gt;It shows that, in case of VPN traffic, that we decrypt before checking the prefilter policy for "Fastpath Trust" action. That is distinct from taking the "Fast Path" which is an unfortunately similar choice of words for how an existing flow is handled (i.e., straight to DAQ for the Firepower Engine processing). The Cisco Live slide does indeed have an error (I believe) in where it shows the output of the prefilter Fastpath action. Nazmul's figure show the correct order - including the ALG and NAT sections.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTD OOO - Nazmul.PNG" style="width: 798px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121953i92BE3CEFE2251E9B/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTD OOO - Nazmul.PNG" alt="FTD OOO - Nazmul.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 15:00:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413661#M1081326</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-06T15:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413662#M1081327</link>
      <description>&lt;P&gt;Hello MHM,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply. So, based on your reply, here is what I conclude. Let me know if this makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 'existing connection' here refer to both the outer IP header connections (IPSec) and inner IP connections. So, if IPsec tunnel is already established (i.e., connection existing) then the tunnel traffic can be fast-pathed, without decryption. If the tunnel connection is new (not existing), then do the VPN decrypt and pass the inner IP to the Access-Control Policy for further inspection. If ACP passes this traffic, a connection entry is added and all future IPSec packets can be fast-pathed without VPN decrypt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 14:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4413662#M1081327</guid>
      <dc:creator>muthumohan</dc:creator>
      <dc:date>2021-06-06T14:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: When exactly "VPN Decrypt" (not SSL decrypt) happens in FTD traffic flow?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4417505#M1081510</link>
      <description>&lt;P&gt;Hi All, I kinda found the answer. In one of the ciscolive videos, I saw that, after VPN Decrypt, the inner-packet is again sent back and checked for "existing connections", this time for the inner-IP.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jun 2021 15:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-when-exactly-quot-vpn-decrypt-quot-not-ssl-decrypt-happens/m-p/4417505#M1081510</guid>
      <dc:creator>muthumohan</dc:creator>
      <dc:date>2021-06-13T15:04:35Z</dc:date>
    </item>
  </channel>
</rss>

