<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA-5220 Decryption Performance Degradation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/259983#M73685</link>
    <description>&lt;P&gt;We have a cluster of PA-5220 firewalls with SSL decryption activated. When initiating a communication across the firewall using a decrypted protocol (scp, HTTPs, etc.) we get 5x slower connections compared to the unencrypted versions of the procotol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Certificate Revocation Checking, CRL and OCSP are unchecked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this behaviour expected? If not, what can be done about it?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Mon, 06 May 2019 13:49:14 GMT</pubDate>
    <dc:creator>an.schall</dc:creator>
    <dc:date>2019-05-06T13:49:14Z</dc:date>
    <item>
      <title>PA-5220 Decryption Performance Degradation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/259983#M73685</link>
      <description>&lt;P&gt;We have a cluster of PA-5220 firewalls with SSL decryption activated. When initiating a communication across the firewall using a decrypted protocol (scp, HTTPs, etc.) we get 5x slower connections compared to the unencrypted versions of the procotol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Certificate Revocation Checking, CRL and OCSP are unchecked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this behaviour expected? If not, what can be done about it?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 13:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/259983#M73685</guid>
      <dc:creator>an.schall</dc:creator>
      <dc:date>2019-05-06T13:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: PA-5220 Decryption Performance Degradation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/260029#M73690</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112493"&gt;@an.schall&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That wouldn't be expected as long as the device is sized appropriately and you aren't close to maxing resources.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To start troubleshooting I would simply look at the resources on the box when you have decryption enabled and see if you notice any high rates. Also with SCP are you decrypting SSH, or are you just decrypting HTTPS traffic for the time being?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 21:22:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/260029#M73690</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-05-06T21:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: PA-5220 Decryption Performance Degradation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/260080#M73711</link>
      <description>&lt;P&gt;Dear BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there a built-in command or dashboard to extract resource usage?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In fact, we tested it with secure copy (scp), hence we are decrypting SSH. The details are the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OpenSSH_6.6.1, OpenSSL 1.0.1i-fips 6 Aug 2014&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;debug1: Local version string SSH-2.0-OpenSSH_6.6.1&lt;/P&gt;&lt;P&gt;debug1: Remote protocol version 2.0, remote software version PaloAltoNetworks_0.2&lt;/P&gt;&lt;P&gt;debug1: no match: PaloAltoNetworks_0.2&lt;/P&gt;&lt;P&gt;debug1: SSH2_MSG_KEXINIT sent&lt;BR /&gt;debug1: SSH2_MSG_KEXINIT received&lt;BR /&gt;debug1: kex: server-&amp;gt;client aes128-ctr hmac-md5 none&lt;BR /&gt;debug1: kex: client-&amp;gt;server aes128-ctr hmac-md5 none&lt;BR /&gt;debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(2048&amp;lt;3072&amp;lt;8192) sent&lt;BR /&gt;debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP&lt;BR /&gt;debug1: SSH2_MSG_KEX_DH_GEX_INIT sent&lt;BR /&gt;debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;Sending file modes: C0600 923309458 foobar.zip&lt;BR /&gt;Sink: C0600 923309458 foobar.zip&lt;BR /&gt;foobar.zip 100% 881MB 17.6MB/s 00:50&lt;BR /&gt;debug1: client_input_channel_req: channel 0 rtype exit-status reply 0&lt;BR /&gt;debug1: channel 0: free: client-session, nchannels 1&lt;BR /&gt;debug1: fd 0 clearing O_NONBLOCK&lt;BR /&gt;debug1: fd 1 clearing O_NONBLOCK&lt;BR /&gt;Transferred: sent 924876344, received 251440 bytes, in 51.3 seconds&lt;BR /&gt;Bytes per second: sent 18016068.0, received 4897.9&lt;BR /&gt;debug1: Exit status 0&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 07:21:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/260080#M73711</guid>
      <dc:creator>an.schall</dc:creator>
      <dc:date>2019-05-07T07:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: PA-5220 Decryption Performance Degradation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/260911#M73965</link>
      <description>&lt;P&gt;Do you have any updates on the issue?&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 13:55:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/260911#M73965</guid>
      <dc:creator>an.schall</dc:creator>
      <dc:date>2019-05-14T13:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: PA-5220 Decryption Performance Degradation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/262190#M74302</link>
      <description>&lt;P&gt;Unfortunately not.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2019 14:24:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-decryption-performance-degradation/m-p/262190#M74302</guid>
      <dc:creator>an.schall</dc:creator>
      <dc:date>2019-05-24T14:24:29Z</dc:date>
    </item>
  </channel>
</rss>

