cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
334
Views
0
Helpful
1
Replies

Drop packets on TLS flows after the "Client Hello" message

Cisco Firepower Threat Defense (FTD) version 7.0.7 related to encrypted traffic.

Our FTD running on 2140 series appliances, the system are dropping packets on TLS flows after the "Client Hello" message after upgrading from 6.4.0.5 to 7.0.7. Telnet is working but HTTPS, SSH and other secure protocol not working. 

Anyone can help on this. Is there anyone face the issue before?

Please help if anyone face the same sort of issue. Now our traffic is working by enabling TCP state bypass for all which is quite risky.

1 Reply 1

nspasov
Cisco Employee
Cisco Employee

A couple of quesitons:

  1. Do you have a TLS/SSL policy in place? If yes, what does that look like
  2. Can you share the output of packet-tracer

Thank you for rating helpful posts!

Thank you for rating helpful posts!
Review Cisco Networking for a $25 gift card