# Decrypting SSL traffic - PMS and egress

**URL:** <https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178>\
**Category:** Technical Forums\
**Tags:** ssl, tls, ltm, application-delivery, tcpdump\
**Created:** [July 20, 2022, 7:32am UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178 "2022-07-20T07:32:34Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bartek](https://avatars.discourse-cdn.com/v4/letter/b/bcef8e/32.png) [@Bartek](https://community.f5.com/u/Bartek)\
**Post date:** [July 20, 2022, 7:32am UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/1 "2022-07-20T07:32:34Z")

</div>

Hi - two questions combined.

Background - trying to catch and decipher tcpdump both for Client → VIP and F5-\> Pool Members traffic

I’m following this tutorial:&nbsp;[Decrypt with tcpdump --f5 ssl](https://clouddocs.f5.com/training/community/adc/html/class4/module1/lab10.html)

I managed to catch the frontend traffic, but I’m struggling with creating the PMS key. I want to automate it using the provided wireshark cmd command, but I get the error:

C:\Program Files\Wireshark: invalid option -- ‘T’  
C:\Program Files\Wireshark: invalid option -- ‘e’

I’m using Wireshark 3.4.8 - what would be the equivalent options for my version? Unfortunately using a Linux in this environment is out of the question. I can only work on Windows stepping stone and can’t send the captures to my PC

Second issue:

Catching the backend traffic does not produce the F5 TLS in the pcap capture… The server ssl profile is present, but I have no idea how to force the --f5 ssl option in tcpdump to catch the keys.

Will appreciate any advice - It is my second day struggling with the issue

---

<div class="post-metadata">

**Author:** ![CA\_Valli](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@CA\_Valli](https://community.f5.com/u/CA_Valli)\
**Post date:** [July 20, 2022, 7:47am UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/2 "2022-07-20T07:47:46Z")

</div>

Hello, I usually use an iRule to log and collect secrets which I’m attaching. This saves info in plain text in LTM file, eventually you can force log rotation and manually bulk-delete all lines from this iRule in “ltm.1” file when you’re done.

To retrieve info and create pms file, run this from bash shell.

```tcl
sed -e 's/^.*\(RSA Session-ID\)/\1/;tx;d;:x' /var/log/ltm > /var/tmp/sessionsecrets.pms
grep -h -o 'CLIENT_RANDOM.*' /var/log/ltm >> /var/tmp/sessionsecrets.pms

```

To import PMS file in wireshark,

Edit → Preferences → Protocols → SSL =\> (Pre)-Master Secret log filename [Browse]

---

<div class="post-metadata">

**Author:** ![Juergen\_Mang](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/juergen_mang/32/12756_2.png) [@Juergen\_Mang](https://community.f5.com/u/Juergen_Mang)\
**Post date:** [July 20, 2022, 9:50am UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/3 "2022-07-20T09:50:58Z")

</div>

You must use tshark NOT wireshark to Automate Pre Master Secret File Creation.

This solution and the solution from CA\_Valli does NOT work for TLS 1.3

To capture backend traffic also you must use the “-i 0.0:nnnp” option for tcpdump.

But it is possible to decrypt TLS 1.3 also, you must extract following fields from the dump:

- CLIENT\_EARLY\_TRAFFIC\_SECRET
- CLIENT\_HANDSHAKE\_TRAFFIC\_SECRET
- SERVER\_HANDSHAKE\_TRAFFIC\_SECRET
- CLIENT\_TRAFFIC\_SECRET\_0
- SERVER\_TRAFFIC\_SECRET\_0

In my tests tshark fails to dump this correctly. My old plan is to create a GitHub repo to upload my script that extracts all pre master secrets for all tls versions.

---

<div class="post-metadata">

**Author:** ![StephanManthey](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@StephanManthey](https://community.f5.com/u/StephanManthey)\
**Post date:** [July 20, 2022, 1:17pm UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/4 "2022-07-20T13:17:11Z")

</div>

Please check this post:

[Knowledge sharing: Troubleshooting/investigating SSL and HTTP issues](https://community.f5.com/topic/298604)

---

<div class="post-metadata">

**Author:** ![David\_Larsen](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/david_larsen/32/33545_2.png) [@David\_Larsen](https://community.f5.com/u/David_Larsen)\
**Post date:** [July 20, 2022, 1:45pm UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/5 "2022-07-20T13:45:08Z")

</div>

You can decrypt TLS1.3 with iRule method but you have to use the correct iRule as here:&nbsp;[https://clouddocs.f5.com/training/community/adc/html/class4/module1/lab12.html#decrypt-ssl-with-irule](https://clouddocs.f5.com/training/community/adc/html/class4/module1/lab12.html#decrypt-ssl-with-irule).

---

<div class="post-metadata">

**Author:** ![David\_Larsen](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/david_larsen/32/33545_2.png) [@David\_Larsen](https://community.f5.com/u/David_Larsen)\
**Post date:** [July 20, 2022, 1:49pm UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/6 "2022-07-20T13:49:23Z")

</div>

You have to use the command line tshark.exe.&nbsp; The other gotcha here is that with Wireshark running you have to have the F5 protocols enabled under Analyze, Enabled Protocols - search for F5 and make sure all the F5 protocols are enabled, otherwise the filters in that commandline will not work properly.&nbsp; Once you enable the protocols in Wireshark GUI then the tshark.exe commandline has them enabled as well.

---

<div class="post-metadata">

**Author:** ![Juergen\_Mang](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/juergen_mang/32/12756_2.png) [@Juergen\_Mang](https://community.f5.com/u/Juergen_Mang)\
**Post date:** [July 20, 2022, 7:06pm UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/7 "2022-07-20T19:06:12Z")

</div>

I have now uploaded my sycript to generate the pms file out of the tcpdump file with enabled sslprovider. This script works for all TLS versions and decrypts clientside and serverside traffic.

I use this script in my daily job and I hope it could help other people also!

> **[GitHub - JuergenMang/f5-tls-decrypt: Creates the Pre Master Secret File from tcpdump...](https://github.com/JuergenMang/f5-tls-decrypt)**
>
> Creates the Pre Master Secret File from tcpdump with enabled f5 sslprovider to decrypt TLS encrypted traffic with Wireshark

---

<div class="post-metadata">

**Author:** ![Leslie\_Hubertus](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/leslie_hubertus/32/11644_2.png) [@Leslie\_Hubertus](https://community.f5.com/u/Leslie_Hubertus)\
**Post date:** [July 26, 2022, 12:11am UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/8 "2022-07-26T00:11:53Z")

</div>

@Bartek &nbsp; - lots of answers here - did any of them get you where you needed to go? If yes, please make sure to mark it as an Accepted Solution so other users with your issue can quickly find help and the author gets credit. 🙂

---

<div class="post-metadata">

**Author:** ![Ichnafi](https://avatars.discourse-cdn.com/v4/letter/i/919ad9/32.png) [@Ichnafi](https://community.f5.com/u/Ichnafi)\
**Post date:** [March 4, 2024, 10:16am UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/9 "2024-03-04T10:16:36Z")

</div>

@Juergen_Mang

thank you for sharing your script.

Sorry to bump this old thread.

For some reason only the client side traffic get’s decrypted. Communication between LTM and nodes are still encrypted. I’m using the tcpdump command as mentioned in your github.

Any idea?

---

<div class="post-metadata">

**Author:** ![Juergen\_Mang](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/juergen_mang/32/12756_2.png) [@Juergen\_Mang](https://community.f5.com/u/Juergen_Mang)\
**Post date:** [March 4, 2024, 11:08am UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/10 "2024-03-04T11:08:08Z")

</div>

This is mostly the case, if:

- tcpdump has not captured the initial tls handshake
- HTTP/2 is used (the -p does not capture all http/2 streams)

Try to add the backend hosts to the filter and always reopen the browser.

---

<div class="post-metadata">

**Author:** ![David\_Larsen](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/david_larsen/32/33545_2.png) [@David\_Larsen](https://community.f5.com/u/David_Larsen)\
**Post date:** [March 4, 2024, 12:12pm UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/11 "2024-03-04T12:12:06Z")

</div>

One thing to take into account is if you have a OneConnect profile applied to the virtual server the Serverside connections could have established SSL handshakes before you take the capture and not be able to be decrypted.&nbsp; You have to make sure all connections on the serverside and clientside are deleted before starting the capture otherwise you may not be able to decrypt.

You should also use a filter that includes the ServerSide nodes specifically and not rely on the :nnnp to gather that data if you are looking to decrypt the serverside traffic.

---

<div class="post-metadata">

**Author:** ![Ichnafi](https://avatars.discourse-cdn.com/v4/letter/i/919ad9/32.png) [@Ichnafi](https://community.f5.com/u/Ichnafi)\
**Post date:** [March 4, 2024, 12:33pm UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/12 "2024-03-04T12:33:18Z")

</div>

Hi,

thank you for your input.

Sadly it does not work.

- did check if any tcp connection exists for this VS
- used a fresh browser
- no oneconnect profile
- no http/2
- added node IPs to tcpdump filter
- one can see complete TCP and SSL handshake between LTM and node in the capture

The LTM still uses a rather old version (15.1), so maybe it’s an issue there?

---

<div class="post-metadata">

**Author:** ![David\_Larsen](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/david_larsen/32/33545_2.png) [@David\_Larsen](https://community.f5.com/u/David_Larsen)\
**Post date:** [March 6, 2024, 2:45pm UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/13 "2024-03-06T14:45:11Z")

</div>

That version should work.

- Is there a ServerSSL profile?
- Is there a HTTPS health monitor?
- Is the pool member IP used in any other pools?

There are a number of ways there could be an open connection to the server that already establish the SSL handshake.&nbsp; I’m wondering if it is something we are not thinking of that could have it open already.

---

<div class="post-metadata">

**Author:** ![Ichnafi](https://avatars.discourse-cdn.com/v4/letter/i/919ad9/32.png) [@Ichnafi](https://community.f5.com/u/Ichnafi)\
**Post date:** [March 8, 2024, 8:26am UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/14 "2024-03-08T08:26:17Z")

</div>

Tried capturing a different VS (with same settings, profiles,..) on the same LTM. This time everything worked as expected.

So, never mind. Your scripts work. Thank you for sharing!

---

<div class="post-metadata">

**Author:** ![David\_Larsen](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/david_larsen/32/33545_2.png) [@David\_Larsen](https://community.f5.com/u/David_Larsen)\
**Post date:** [March 8, 2024, 1:50pm UTC](https://community.f5.com/t/decrypting-ssl-traffic-pms-and-egress/70178/15 "2024-03-08T13:50:41Z")

</div>

Glad that one is working.&nbsp; If you would like to figure out where the open connection is I would do a quick tcpdump on the serverside of just that server and see if you can see an open connection and where it might be coming from.&nbsp; I suspect once you get that connection to reset you will be able to capture from the original VS.
