07-06-2017 02:36 PM - edited 03-12-2019 02:40 AM
We are experiencing decryption issue with our two ASA 5555-x \Firepower appliances. We are receiving " ERR_SSL_Protocol_ERROR" when visiting sites. Restarting the browser temporarily resolves the issue, and disabling SSL decryption permanently resolves the issue. This is happening for various browsers and depending on the browser, the displayed message is different.
We run a WireShark trace and discovered the following error " TLSv1.2 alert level fatal, bad record MAC" within the trace. We have tried to add sites to the Trusted sites and ensure the Internet Time was sync'd with the computer time both were solution found during our research but no success with either. Any assistance in this matter would be greatly appreciated.
07-06-2017 06:59 PM
Does it occur for all SSL/TLS traffic or only for certain sites?
If the latter, it could be that they are resistant to man-in-the-middle by virtue of using certificate pinning or similar techniques. In those cases, you need to exempt the sites from your SSL policy.
If the former, it could be either an error in your FMC certificate (make sure it has a 2048-bit RSA key) or potentially a bug with Firepower.
If you aren't running the latest Firepower (6.2.0.2 as of right now), TAC will probably suggest you do so if you open a ticket on the issue.
05-22-2018 11:32 PM
Same problem. FP versions 6.2.2 and 6.2.3 both have it.
Reloading the page works, but the first attempt to open the website often fails with "ERR_SSL_DECRYPT_ERROR_ALERT" in Chrome.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide