Questions about the decryption performance of pa-5200 series

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Questions about the decryption performance of pa-5200 series

L3 Networker
The customer configures inbound decryption on the firewall. 
When the decrypted traffic exceeds the processing performance of the firewall,
the firewall will not decrypt the traffic that needs to be decrypted. Will it be processed as normal traffic?
Can anyone explain this, thanks
1 REPLY 1

L2 Linker

Hi @Felixcao

 

this is documented under the decryption profile settings in the GUI. Alternatively, you can have a look at Techdoc 

https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-web-interface-help/objects/objects-decryption-p...

 

You have the option to terminate the sessions when resources are not available on the firewall. By default, this option is not checked. 

Block sessions if resources not available
Terminate sessions if system resources are not available to process decryption.
Whether to block sessions when resources aren’t available is a tradeoff between tighter security and a better user experience. If you don’t block sessions when resources aren’t available, the firewall won’t be able to decrypt traffic that you want to decrypt when resources are impacted. However, blocking sessions when resources aren’t available may affect the user experience because sites that are normally reachable may become temporarily unreachable.

 

If you do not block the sessions when resources are not available, the traffic will go through encrypted provided that there is a security rule allowing it, but uninspected.

 

Regards

 

--Richard

  • 340 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!