How did your SSL Decryption deployment go?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How did your SSL Decryption deployment go?

L2 Linker

We are in the process of making a case to deploy SSL Decryption. While I am sure this will happen, predeployment, I would like to hear any horror stories or even success stories on how your deployment went. Also any do's and dont's would be fantastic. Currently our environment is 4.1.7-h2 if that is a factor in your deployment stories, that much better.

Thanks!

1 REPLY 1

L6 Presenter

Back in spring 2010 I stumbled upon a bug in the 2000-series which ended up having the userid process crash and by that pointing out the wrong user in the logs (terminalserver environment so running ts-client on the servers). This was due to that the cert's used for termination is generated on the fly by the mgmtplane in the 2000-series which had a bit too much to do which then had other sideeffects such as crashing the userid-process.

I think one of the fixes PA implemented was to expand the use of the internal watchdog (so when for example userid crashes it should automagically get restarted).

However the above should have been fixed back in 2010 and I havent heard of any further issues regarding this since then.

So things to lookout for:

1) Configuration - I prefer to terminate everything (some argue that banking sites or such shouldnt be terminated so it depends on your local policy however even banking sites can contain malware).

2) Rated ssl-performance (concurrent sessions) for the appliance you selected - more and more traffic uses https nowadays: facebook, gmail, hotmail, twitter etc. And the same goes for malware - more and more malwares uses ssl to protect their communications (and because TCP443 is often open for outbound connections with no ssl-termination in place).

3) Test the device in production - I found out this bug with userid (caused by ssl-termination) by accident when I tested an url and tried to locate it in the logs afterwards, I saw some other userid instead of my own. Even if this particular bug is fixed since many years its always good to know your hardware and to verify that its always performing correctly.

  • 1984 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!