<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL proxy allocation error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-proxy-allocation-error/m-p/230214#M66184</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The 5020 has a relatively small Max concurrent decryption sessions limit of 15,872 in comparison to the rest of the platform limits. One way to get around this would be to take a look at what exactly you are decrypting and seeing if you can potentially leave out some traffic that you don't really care about.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Otherwise if you have that nailed down to simply what you require to actually be decrypted; then your solution would really be as you already stated, move it to a proxy or upgrade the hardware. Keeping in mind that the *200 series (5200/3200) are vastly better spec'd and the 5220 would bring you all the way up to 400,000 Max concurrent decryption sessions sessions.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Sep 2018 17:58:27 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-09-10T17:58:27Z</dc:date>
    <item>
      <title>SSL proxy allocation error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-proxy-allocation-error/m-p/230206#M66182</link>
      <description>&lt;P&gt;I had ssl decryption in place on PA_5020 and it seems like during peak times, my internal data traffic is reaching max ssl decryption session limit and those beyond the limit are shown as decrypt error and are sent un-decrypted. Is there any solution for this besides hardware upgrade, offload ssl decrypt to proxy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 17:23:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-proxy-allocation-error/m-p/230206#M66182</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2018-09-10T17:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSL proxy allocation error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-proxy-allocation-error/m-p/230214#M66184</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The 5020 has a relatively small Max concurrent decryption sessions limit of 15,872 in comparison to the rest of the platform limits. One way to get around this would be to take a look at what exactly you are decrypting and seeing if you can potentially leave out some traffic that you don't really care about.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Otherwise if you have that nailed down to simply what you require to actually be decrypted; then your solution would really be as you already stated, move it to a proxy or upgrade the hardware. Keeping in mind that the *200 series (5200/3200) are vastly better spec'd and the 5220 would bring you all the way up to 400,000 Max concurrent decryption sessions sessions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 17:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-proxy-allocation-error/m-p/230214#M66184</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-10T17:58:27Z</dc:date>
    </item>
  </channel>
</rss>

