I have Host A talking to Server B with 587 SMTP with STARTTLS
A uses only Ciphers that are not supported by B and B closes the connection after A sent the TLS Client Hello.
Now we have a firewall rule that has IPS enabled, nothing else:
The handshake failure between A and B on Port 587 is logged in SSL /TLS log of the firewall. I do not expect it to be logged there. The destination Server is also in local TLS Exclusion Group.
Is the Firewall trying to decrypt the traffic anyway?
Do we need to excluse the traffic on shell? I would not like that.
This thread was automatically locked due to age.