<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Decryption is not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/decryption-is-not-working/m-p/4886985#M1102728</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;Decryption is not happening on windows vm which is residing behind the cisco FTD,&lt;/P&gt;&lt;P&gt;I followed below steps for generate the certificate.&lt;/P&gt;&lt;P&gt;1. openssl genrsa -out server.key 4096&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;openssl req -new -key server.key -out server.csr&lt;/P&gt;&lt;P&gt;3.&amp;nbsp;openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt&lt;/P&gt;&lt;P&gt;4. Import CA manually, uploaded the ablove generated certificate and key.&lt;/P&gt;&lt;P&gt;5. Download the certificate from internal CA of FMC and installed on windows vm.&lt;/P&gt;&lt;P&gt;6. Created the SSL policy with decrypt-resign. but when i am trying to access any website from windows vm its giving me ssl error.&lt;/P&gt;&lt;P&gt;but in bowser certificate its showing the certificate which i installed.&lt;/P&gt;&lt;P&gt;Need your support here, what else needs to be done.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;//Bharat&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jul 2023 13:44:16 GMT</pubDate>
    <dc:creator>bharat.bhushan.mehta</dc:creator>
    <dc:date>2023-07-18T13:44:16Z</dc:date>
    <item>
      <title>Decryption is not working</title>
      <link>https://community.cisco.com/t5/network-security/decryption-is-not-working/m-p/4886985#M1102728</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;Decryption is not happening on windows vm which is residing behind the cisco FTD,&lt;/P&gt;&lt;P&gt;I followed below steps for generate the certificate.&lt;/P&gt;&lt;P&gt;1. openssl genrsa -out server.key 4096&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;openssl req -new -key server.key -out server.csr&lt;/P&gt;&lt;P&gt;3.&amp;nbsp;openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt&lt;/P&gt;&lt;P&gt;4. Import CA manually, uploaded the ablove generated certificate and key.&lt;/P&gt;&lt;P&gt;5. Download the certificate from internal CA of FMC and installed on windows vm.&lt;/P&gt;&lt;P&gt;6. Created the SSL policy with decrypt-resign. but when i am trying to access any website from windows vm its giving me ssl error.&lt;/P&gt;&lt;P&gt;but in bowser certificate its showing the certificate which i installed.&lt;/P&gt;&lt;P&gt;Need your support here, what else needs to be done.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;//Bharat&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 13:44:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/decryption-is-not-working/m-p/4886985#M1102728</guid>
      <dc:creator>bharat.bhushan.mehta</dc:creator>
      <dc:date>2023-07-18T13:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption is not working</title>
      <link>https://community.cisco.com/t5/network-security/decryption-is-not-working/m-p/4903591#M1103368</link>
      <description>&lt;P&gt;Hi Bharat,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If you elect to decrypt and re-sign traffic, the system acts as a man-in-the-middle.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, the user types in &lt;A href="https://www.cisco.com" target="_blank"&gt;https://www.cisco.com&lt;/A&gt; in a browser. The traffic reaches the FTD device, the device then negotiates with the user using the CA certificate specified in the rule and builds an SSL tunnel between the user and the FTD device. At the same time the device connects to &lt;A href="https://www.cisco.com" target="_blank"&gt;https://www.cisco.com&lt;/A&gt; and creates an SSL tunnel between the server and the FTD device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thus, the user sees the CA certificate configured for the SSL decryption rule instead of the certificate from &lt;A href="http://www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt;. The user must trust the certificate to complete the connection. The FTD device then performs decryption/re-encryption in both directions for traffic between the user and destination server.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(88,88,91);font-size:14px;"&gt;If the client does not trust the CA used to re-sign the server certificate, it warns the user that the certificate should not be trusted. To prevent this, import the CA certificate into the client trusted CA store. Alternatively, if your organization has a private PKI, you can issue an intermediate CA certificate signed by the root CA which is automatically trusted by all clients in the organization, then upload that CA certificate to the device.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(88,88,91);font-size:14px;"&gt;Please refer this link to check steps again : &lt;/SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/623/fdm/fptd-fdm-config-guide-623/fptd-fdm-ssl-decryption.html" target="_blank"&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(88,88,91);font-size:14px;"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/623/fdm/fptd-fdm-config-guide-623/fptd-fdm-ssl-decryption.html&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also on FMC you can check for SSL events that will give you more details about the error which will help fix the config. If possible can you hsare that screenshot here?&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;-----------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;You can also learn more about Secure Firewall (formerly known as NGFW) through our live Ask the Experts (ATXs) session. Check out Cisco Network Security ATXs Resources [&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493&lt;/A&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;-----------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;Divya Jain&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 07:19:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/decryption-is-not-working/m-p/4903591#M1103368</guid>
      <dc:creator>Divya Jain</dc:creator>
      <dc:date>2023-08-11T07:19:20Z</dc:date>
    </item>
  </channel>
</rss>

