<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL decryption exception fail in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssl-decryption-exception-fail/m-p/5327251#M1122583</link>
    <description>&lt;P&gt;There is option to select tls 1.3 in ssl policy and tls 1.3 decryption&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before downgrade check these options&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you can capture traffic in ftd interface and check tls ver use&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Thu, 04 Sep 2025 18:55:58 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-09-04T18:55:58Z</dc:date>
    <item>
      <title>SSL decryption exception fail</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-exception-fail/m-p/5327226#M1122579</link>
      <description>&lt;P&gt;I'm working on creating an SSL decryption policy, but I'm running into an issue where the "no decryption" rule is failing to prevent decryption.&lt;/P&gt;&lt;P&gt;Interestingly, if I configure the "no decryption" rule using a subnet address, it works as expected. However, when I use a URL in the rule, it doesn't seem to have any effect.&lt;/P&gt;&lt;P&gt;Am I missing something here? These same rules used to work fine in version 7.4.2, but they no longer work in 7.6.2.&lt;/P&gt;&lt;P&gt;Any insights would be appreciated.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rules.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251390i021EBB0E1B24D1C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="rules.jpg" alt="rules.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 17:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-exception-fail/m-p/5327226#M1122579</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-09-04T17:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption exception fail</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-exception-fail/m-p/5327241#M1122580</link>
      <description>&lt;P&gt;The key here I think is tls 1.2 vs tls 1.3&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 18:39:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-exception-fail/m-p/5327241#M1122580</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-04T18:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption exception fail</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-exception-fail/m-p/5327246#M1122581</link>
      <description>&lt;P&gt;I would agree that it could be a problem, firewall not being able to look at the certificate and match URL, but it was working prior to upgrade to 7.6.2, so maybe is anoter sort of problem. I'll reset the firewall and try again with the previous version.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 18:51:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-exception-fail/m-p/5327246#M1122581</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-09-04T18:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSL decryption exception fail</title>
      <link>https://community.cisco.com/t5/network-security/ssl-decryption-exception-fail/m-p/5327251#M1122583</link>
      <description>&lt;P&gt;There is option to select tls 1.3 in ssl policy and tls 1.3 decryption&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before downgrade check these options&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you can capture traffic in ftd interface and check tls ver use&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 18:55:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-decryption-exception-fail/m-p/5327251#M1122583</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-04T18:55:58Z</dc:date>
    </item>
  </channel>
</rss>

