<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 4100 SSL features in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-4100-ssl-features/m-p/3430906#M132912</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gillermo Gonzalez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i understand your questions right:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. When a certificate isn't trusted you will get a certificate warning as this: &lt;A href="http://help.37signals.com/attachments/images/36/scaled/certificate%20error.png" title="http://help.37signals.com/attachments/images/36/scaled/certificate%20error.png"&gt;http://help.37signals.com/attachments/images/36/scaled/certificate%20error.png&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should beable to achive this with GPOs for almost all endpoint, please beaware that Firefox etc. will use cert-pinning soon, and SSL/TLS inspection won't be an option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. You can create rules based on the traffic and certificates. As far as i know its not an option to send the traffic decrypted to another unit - then you should put your FTD unit into IDS insted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Side remark, to enable Hardware Decryption: system support ssl-hw-offload enable in FXOS)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 May 2018 12:24:32 GMT</pubDate>
    <dc:creator>Nikolaj Pabst</dc:creator>
    <dc:date>2018-05-29T12:24:32Z</dc:date>
    <item>
      <title>Firepower 4100 SSL features</title>
      <link>https://community.cisco.com/t5/network-security/firepower-4100-ssl-features/m-p/3430905#M132911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;I´m working with some RFP questions.&amp;nbsp; The customer has implemented Firepower 4140 and they was waiting hardware acceleration support to implement SSL policies.&lt;/P&gt;&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;Now the customer launched a RFP to check if they configure SSL policies or work with another solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;Please your help with the following questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1" style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN class="s1"&gt;- High Certificate Warnings:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; &lt;SPAN style="color: #232323;"&gt;For certificate reassign, how are warnings communicated to endpoints when an invalid certificate is detected?&lt;/SPAN&gt; &lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1" style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN style="color: #232323;"&gt;- High Certificate Errors:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Should the SSL system connect to an SSL server with an invalid certificate, are there options to ignore and pass through the message to the endpoint or drop the connection based upon predefined configuration (e.g. ignore expired certificate warnings and pass warning to endpoint, block connections using self-signed certificates)?&lt;/SPAN&gt; &lt;/P&gt;&lt;P class="p3"&gt;&lt;/P&gt;&lt;P class="p1" style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;&lt;SPAN class="s3"&gt;- High Device Chaining:&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; &lt;SPAN style="color: #232323;"&gt;Can the system send unencrypted traffic to multiple devices, both inline and passive, in a defined chain (e.g. inline NGIPS e inline advanced malware detection e passive DLP)?&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;- High Traffic Management:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #232323;"&gt;Can the system send defined traffic (OSI layer 2/3/4/7) to different attached devices? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;Thank in advance,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2018 14:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-4100-ssl-features/m-p/3430905#M132911</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2018-05-16T14:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 4100 SSL features</title>
      <link>https://community.cisco.com/t5/network-security/firepower-4100-ssl-features/m-p/3430906#M132912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gillermo Gonzalez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i understand your questions right:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. When a certificate isn't trusted you will get a certificate warning as this: &lt;A href="http://help.37signals.com/attachments/images/36/scaled/certificate%20error.png" title="http://help.37signals.com/attachments/images/36/scaled/certificate%20error.png"&gt;http://help.37signals.com/attachments/images/36/scaled/certificate%20error.png&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should beable to achive this with GPOs for almost all endpoint, please beaware that Firefox etc. will use cert-pinning soon, and SSL/TLS inspection won't be an option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. You can create rules based on the traffic and certificates. As far as i know its not an option to send the traffic decrypted to another unit - then you should put your FTD unit into IDS insted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Side remark, to enable Hardware Decryption: system support ssl-hw-offload enable in FXOS)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2018 12:24:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-4100-ssl-features/m-p/3430906#M132912</guid>
      <dc:creator>Nikolaj Pabst</dc:creator>
      <dc:date>2018-05-29T12:24:32Z</dc:date>
    </item>
  </channel>
</rss>

