<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072078#M136272</link>
    <description>&lt;P&gt;Thank.&lt;/P&gt;
&lt;P&gt;I get it.&lt;/P&gt;
&lt;P&gt;For SSL, I think firewall proxy the communcation. It send client its own certificate and client verifies it.After then, firewall create SSL connection to the other client.So there are two SSL connection.&lt;/P&gt;
&lt;P&gt;Am I right?&lt;/P&gt;</description>
    <pubDate>Tue, 25 Apr 2017 14:22:09 GMT</pubDate>
    <dc:creator>kyisoethin</dc:creator>
    <dc:date>2017-04-25T14:22:09Z</dc:date>
    <item>
      <title>Can firewall decrypt SSL or other encrypted traffic ?</title>
      <link>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072073#M136260</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to know if firewall can decrypt encrypted traffic.&lt;/P&gt;
&lt;P&gt;If so, which firewall can do so.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:15:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072073#M136260</guid>
      <dc:creator>kyisoethin</dc:creator>
      <dc:date>2019-03-12T09:15:19Z</dc:date>
    </item>
    <item>
      <title>Hi kyisoethin,</title>
      <link>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072074#M136263</link>
      <description>&lt;P&gt;Hi kyisoethin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No, Cisco ASA's have ability to decrypt encrypted traffic but Cisco ASA 5500-x series firewall with firepower modules has the ability to decrypt and inspect the SSL traffic. Follow the link for more information.&lt;/P&gt;
&lt;P&gt;https://www.a10networks.com/blog/ssl-inspection-decryption-cisco-asa-firepower&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;But other vendors firewalls like PALO ALTO can do. Follow the link for more information.&lt;/P&gt;
&lt;P&gt;https://www.paloaltonetworks.com/features/decryption&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If this is helpful,&lt;SPAN&gt;&amp;nbsp;please give it a thumbs up.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 13:28:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072074#M136263</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-04-24T13:28:57Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072075#M136265</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ordinary firewalls which perform firewalling functions only such as ASA can deycrpt IPSec traffic only which is encrypted. SSL can't be decrypted with ordinary firewalls.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The next Gen firewalls can decrypt ssl traffic and intercept it. This needs lot of processing power which isn't present in ordinary firewalls.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 13:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072075#M136265</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2017-04-24T13:35:22Z</dc:date>
    </item>
    <item>
      <title>Thank you for your annswer.</title>
      <link>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072076#M136267</link>
      <description>&lt;P&gt;Thank you for your annswer.&lt;/P&gt;
&lt;P&gt;I have more question about it.&lt;/P&gt;
&lt;P&gt;If firewall can decrypt Ipsec or ssl, how can this be ?&lt;/P&gt;
&lt;P&gt;How do they get decryption encryption key ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 03:02:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072076#M136267</guid>
      <dc:creator>kyisoethin</dc:creator>
      <dc:date>2017-04-25T03:02:55Z</dc:date>
    </item>
    <item>
      <title>For IPSec, the common</title>
      <link>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072077#M136270</link>
      <description>&lt;P&gt;For IPSec, the common deployment is using Pre-Shared key which needs to be configured at both firewall ends. This is the key used conceptually to encrypt/decrypt. You can look for exact way of encryption/decryption as IPSec IKEv1 goes through phase 1 and phase 2. During this negotiation, it will extract the actual encryption key, authentication key and nounce.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For SSL, it is based on cryptography. The user will authenticate the firewall certificate using its trusted root CA. After successful verification, they will use public key/private key to exchange session-key which will be used during the session life for encryption/decryption. This is the case for client and client-less.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can lookup more online to get the details about how this happens as its lengthy process&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 04:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072077#M136270</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2017-04-25T04:56:54Z</dc:date>
    </item>
    <item>
      <title>Thank.</title>
      <link>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072078#M136272</link>
      <description>&lt;P&gt;Thank.&lt;/P&gt;
&lt;P&gt;I get it.&lt;/P&gt;
&lt;P&gt;For SSL, I think firewall proxy the communcation. It send client its own certificate and client verifies it.After then, firewall create SSL connection to the other client.So there are two SSL connection.&lt;/P&gt;
&lt;P&gt;Am I right?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 14:22:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072078#M136272</guid>
      <dc:creator>kyisoethin</dc:creator>
      <dc:date>2017-04-25T14:22:09Z</dc:date>
    </item>
    <item>
      <title>Correct.</title>
      <link>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072079#M136273</link>
      <description>&lt;P&gt;Correct.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 14:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firewall-decrypt-ssl-or-other-encrypted-traffic/m-p/3072079#M136273</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-04-25T14:23:03Z</dc:date>
    </item>
  </channel>
</rss>

