cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3321
Views
5
Helpful
2
Replies

URL Filtering with TLS 1.3

david.campeau
Level 1
Level 1

With forward secrecy in TLS 1.3, how is the FMC/FTD going to handle TLS 1.3 specifically with URL filtering?  This is just around the corner, so I was wondering if there were any work-arounds as the FTD will not be able to pull the certificate from the TLS handshake to determine domains. 

1 Accepted Solution

Accepted Solutions

aaron.hackney
Level 1
Level 1

Hi David, 

You will need to terminate the SSL connections at the FTD and do full man-in-the-middle SSL proxy. I believe that the Firepower teams are working on adding TLS 1.3 draft 28 support to future releases.

 

I have done a short write up on URL filtering and TLS 1.3 here if you are interested: https://hacksbrain.com/2018/07/25/tls-1-3-ramifications/

 

Hope that helps!

-A

View solution in original post

2 Replies 2

aaron.hackney
Level 1
Level 1

Hi David, 

You will need to terminate the SSL connections at the FTD and do full man-in-the-middle SSL proxy. I believe that the Firepower teams are working on adding TLS 1.3 draft 28 support to future releases.

 

I have done a short write up on URL filtering and TLS 1.3 here if you are interested: https://hacksbrain.com/2018/07/25/tls-1-3-ramifications/

 

Hope that helps!

-A

Good information as well as a good write up -- Thanks for the info.

 

 

Review Cisco Networking products for a $25 gift card