<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TLS Server Identity Discovery Causing Possible Issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4784270#M1098245</link>
    <description>&lt;P&gt;We are running version 7.2.2.&amp;nbsp; We are not doing any SSL decryption on traffic.&amp;nbsp; We just have the TLS Server Identity Discovery setting enabled under Advanced Options in our ACP.&amp;nbsp; See screenshot below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmeetze_0-1677605860645.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177752i9948816A997D60A5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmeetze_0-1677605860645.png" alt="jmeetze_0-1677605860645.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Feb 2023 17:38:27 GMT</pubDate>
    <dc:creator>jmeetze</dc:creator>
    <dc:date>2023-02-28T17:38:27Z</dc:date>
    <item>
      <title>TLS Server Identity Discovery Causing Possible Issues</title>
      <link>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4772127#M1097643</link>
      <description>&lt;P&gt;We recently installed new FTD's and have the option enabled under the Advanced Settings of our ACP for "TLS Server Identity Discovery".&amp;nbsp; Yesterday, we had an external user who was having issues accessing our main website.&amp;nbsp; FMC logs showed allows and no drops for this users traffic to the site.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After reviewing logs of all traffic flow down to our load balancers, I found "TCP_Conn_Terminate" logs from the server.&amp;nbsp; I verified that this user had no issues access two other sites which go through our FTD.&amp;nbsp; The only difference in the sites was that the one that wasn't working is using TLS 1.3.&amp;nbsp; To resolve the issue, I had to create a FastPath rule in our pre-filter policy.&amp;nbsp; I'm still not sure why this setting would be the cause of the issue or if it could have been something else.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else had issues with enabling this setting when your sites are using TLS 1.3 server certificates?&amp;nbsp; Is there any other option other than to create a FastPath rule to bypass all inspection?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 14:07:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4772127#M1097643</guid>
      <dc:creator>jmeetze</dc:creator>
      <dc:date>2023-02-09T14:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Server Identity Discovery Causing Possible Issues</title>
      <link>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4784267#M1098244</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Can you tell what is the &amp;nbsp;FTD version that you are running?&lt;BR /&gt;It could be compatibility issue with TLS 1.3 but we do need to check logs / captures to verify more. &amp;nbsp;Can you also share screenshot or details about your current SSL policy config?&lt;BR /&gt;&amp;nbsp;Older versions had issue with TLS1.3 but with newer version shouldnt be an issue.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;-----------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;You can also learn more about Secure Firewall (formerly known as NGFW) through our live Ask the Experts (ATXs) session. Check out Cisco Network Security ATXs Resources [&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493&lt;/A&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;-----------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Divya Jain&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 17:32:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4784267#M1098244</guid>
      <dc:creator>Divya Jain</dc:creator>
      <dc:date>2023-02-28T17:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Server Identity Discovery Causing Possible Issues</title>
      <link>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4784270#M1098245</link>
      <description>&lt;P&gt;We are running version 7.2.2.&amp;nbsp; We are not doing any SSL decryption on traffic.&amp;nbsp; We just have the TLS Server Identity Discovery setting enabled under Advanced Options in our ACP.&amp;nbsp; See screenshot below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmeetze_0-1677605860645.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177752i9948816A997D60A5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmeetze_0-1677605860645.png" alt="jmeetze_0-1677605860645.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 17:38:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4784270#M1098245</guid>
      <dc:creator>jmeetze</dc:creator>
      <dc:date>2023-02-28T17:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Server Identity Discovery Causing Possible Issues</title>
      <link>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4785128#M1098273</link>
      <description>&lt;P&gt;I had a customer facing this same issue with 7.2.2 and using the Bomgar remote control software. TAC also advised them to use Fastpath. This was the identified bug:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd80741" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd80741&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I would not be surprised to see other applications affected.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 15:33:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4785128#M1098273</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-03-01T15:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Server Identity Discovery Causing Possible Issues</title>
      <link>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4792801#M1098636</link>
      <description>&lt;P&gt;Bomgar works with FTD 7.3 and &lt;SPAN&gt;TLS Server Identity Discovery enabled&lt;/SPAN&gt;. Oddly, FTD 7.2.3 (recently released), Bomgar still doesn't work with &lt;SPAN&gt;TLS Server Identity Discovery enabled&lt;/SPAN&gt;. The other odd thing with 7.3 though, I've had issues with remote FTD registration and need to fast path the connection to the remote FTD. I suppose it's recommended to fast path management traffic though....&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 14:12:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-server-identity-discovery-causing-possible-issues/m-p/4792801#M1098636</guid>
      <dc:creator>Jack G</dc:creator>
      <dc:date>2023-03-13T14:12:19Z</dc:date>
    </item>
  </channel>
</rss>

