<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use MP SSL Session Cache in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/use-mp-ssl-session-cache/m-p/237789#M68131</link>
    <description>&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;Going forward will do that.&lt;/P&gt;&lt;P&gt;PAN OS&amp;nbsp;8.0.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;model: PA-5220&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show system setting ssl-decrypt session-cache&lt;/P&gt;&lt;P&gt;Queued message buffers to MP: 0&lt;BR /&gt;Total messages to MP: 103628501 (1984004)&lt;BR /&gt;hosts (client/server) id/ticket age cipher_c cipher_s user&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will not modify the settings.&lt;/P&gt;&lt;P&gt;I see there lot of sssl conenctions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are these SSL conections for active traffic?&lt;/P&gt;&lt;P&gt;Can you please explain me in more detail cache ssl sessions in MP?&lt;/P&gt;</description>
    <pubDate>Tue, 30 Oct 2018 15:10:39 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2018-10-30T15:10:39Z</dc:date>
    <item>
      <title>Use MP SSL Session Cache</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-mp-ssl-session-cache/m-p/237644#M68090</link>
      <description>&lt;P&gt;when i run the below command&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show system setting ssl-decrypt setting&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vsys : vsys1&lt;BR /&gt;Forward Proxy Ready : yes&lt;BR /&gt;Inbound Proxy Ready : no&lt;BR /&gt;Disable ssl : no&lt;BR /&gt;Disable ssl-decrypt : no&lt;BR /&gt;Notify user : no&lt;BR /&gt;Proxy for URL : no&lt;BR /&gt;Wait for URL : yes&lt;BR /&gt;Block revoked Cert : yes&lt;BR /&gt;Cert Status Query Timeout : 5&lt;BR /&gt;URL Category Query Timeout : 5&lt;BR /&gt;Fwd proxy server cert's rsa key size: 0&lt;BR /&gt;Fwd proxy server cert's ecdsa key size: 0&lt;BR /&gt;Use Cert Cache : yes&lt;BR /&gt;Verify CRL : no&lt;BR /&gt;Verify OCSP : no&lt;BR /&gt;CRL Status receive Timeout : 5&lt;BR /&gt;OCSP Status receive Timeout : 5&lt;BR /&gt;&lt;FONT color="#993300"&gt;Use MP SSL Session Cache : yes&lt;/FONT&gt;&lt;BR /&gt;Use TCP SACK Option : yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to understand do we use MP for ssl decryt???????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 17:39:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-mp-ssl-session-cache/m-p/237644#M68090</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-29T17:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Use MP SSL Session Cache</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-mp-ssl-session-cache/m-p/237784#M68128</link>
      <description>&lt;P&gt;Please include your PAN-OS version and platform if possible when posting questions, it can really help in diagnosing issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some platforms (such as PA-5000 and the older PA-7000 NPCs) don't have enough memory on the DP to effectively cache SSL sessions compared to how many decryption sessions they support. The setting you see leverages the MP memory to store the SSL session cache instead, giving the system the ability to effectively keep up with the demand of the platform. It's enabled by default, and can be modified by:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&amp;gt; configure
# set deviceconfig setting ssl-decrypt use-mp-sess-cache &amp;lt;yes|no&amp;gt;
# commit&lt;/PRE&gt;&lt;P&gt;I wouldn't recommend touching it though, since it is working as designed. Removing it could cause your DP CPU to increase since it has less cache space for resuming previously-negotiated decrypted SSL (TLS) sessions. You can see&amp;nbsp;the cache&amp;nbsp;activity with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&amp;gt; show system setting ssl-decrypt session-cache &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 14:58:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-mp-ssl-session-cache/m-p/237784#M68128</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-10-30T14:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: Use MP SSL Session Cache</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-mp-ssl-session-cache/m-p/237789#M68131</link>
      <description>&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;Going forward will do that.&lt;/P&gt;&lt;P&gt;PAN OS&amp;nbsp;8.0.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;model: PA-5220&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show system setting ssl-decrypt session-cache&lt;/P&gt;&lt;P&gt;Queued message buffers to MP: 0&lt;BR /&gt;Total messages to MP: 103628501 (1984004)&lt;BR /&gt;hosts (client/server) id/ticket age cipher_c cipher_s user&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will not modify the settings.&lt;/P&gt;&lt;P&gt;I see there lot of sssl conenctions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are these SSL conections for active traffic?&lt;/P&gt;&lt;P&gt;Can you please explain me in more detail cache ssl sessions in MP?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 15:10:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-mp-ssl-session-cache/m-p/237789#M68131</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-30T15:10:39Z</dc:date>
    </item>
  </channel>
</rss>

