cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2046
Views
0
Helpful
4
Replies

Cisco FirePOWER SSL Block

chris.makely
Level 1
Level 1

Currently using FirePOWER, experiencing an unexpected SSL Block for some traffic, SSL rule has been created not to decrypt the traffic, URLs that are being accessed are whitelisted, SSL Flow error is Defer Cut Post CCs (0x0000197), SSL version TLSV1.2, The SSL flow flags show the handshake to be complete but yet FirePOWER is still blocking the traffic, I have an access policy for the internal source to allow all traffic from any network, any insight would be greatly appreciated. The service attempting to access my internal VMS is WISENet WAVESync 

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

Have you tried a packet capture with trace while filtering on the interesting traffic?

Marvin, 

 

I have not yet, that was my next step, i'll post with that data soon, thank you for the insight 

Isaac Smith
Level 1
Level 1

Probably a long shot but I am also seeing this.  We enabled a monitor only rule to check for TLS versions and then a default rule of do not decrypt but still see a SSL block with that same SSL error which I find odd  DEFER_CUT_POST_CCS

tato386
Level 6
Level 6

same exact error here.  firepower ignores the "do not decrypt" SSL rule and gets blocked by default SSL rule.  undecryptable actions are both block so no help there.

Review Cisco Networking products for a $25 gift card