- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-24-2015 05:17 AM
Hi Team,
My doubt is that,..doing SSL decryption will increase the number of sessions?
example : if i access gmail there will be one tunnel established to the server (gmail) inside which text chat, video chat, other apps will be there.
Now if i enable SSL decryption will it increase the number of sessions as now it can see each and every activity and application inside the gmail.
Regards,
Guru
08-24-2015 08:41 AM
There is a limit on number of session a firewall can decrypt. Check the following document.
https://live.paloaltonetworks.com/t5/Articles/How-to-Implement-and-Test-SSL-Decryption/ta-p/59719
08-25-2015 03:22 AM
SSL decryption does not impact your session count.
As Guru, mentions there is a separate limit for the number of active decryption sessions.
SSL decryption also impacts processing on the firewall so you should add this in stages to be sure you don't overload the capacity of the device.
This is a good overview on how to ease in decryption.
https://live.paloaltonetworks.com/t5/Articles/Controlling-SSL-Decryption/ta-p/56218
08-28-2015 11:08 PM
Hi Guru,
just to clarify - your previously encrypted sessions were showing as SSL and now they will show as the chat, video chat, etc. Number of overall sessions will not increase, you will only have better visibility into the content of some of those sessions that were previously encrypted. So, answer is no, number of sessions will not increase, it will just be less ssl sessions and more of the web-browsing and whatever other application is found within the encrypted flow.
Best regards
Luciano
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!