- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-26-2023 11:30 PM
Hello all,
When the SSL Decryption Session is full, the customer asks how the non-decryption traffic is handled.
We need information about whether the lack of resources is causing random drops or not being affected.
The current model is VM-700, VM-300 and the OS is 9.1.14. CPU and Memory are set to Allow maximum.
Kind regards,
04-27-2023 05:39 AM
If you are performing decryption then it depends on how decryption profile is configured.
Objects > Decryption > Decryption Profile
"Block sessions if resources not available"
If checkbox is not checked then sessions will pass through but won't be decrypted.
If checked then additional sessions won't be allowed.
Imagine someone wanting to get out your network bypassing decryption it is possible to initiate loads of ssl sessions until firewall starts bypassing new sessions without decryption.
04-27-2023 05:39 AM
If you are performing decryption then it depends on how decryption profile is configured.
Objects > Decryption > Decryption Profile
"Block sessions if resources not available"
If checkbox is not checked then sessions will pass through but won't be decrypted.
If checked then additional sessions won't be allowed.
Imagine someone wanting to get out your network bypassing decryption it is possible to initiate loads of ssl sessions until firewall starts bypassing new sessions without decryption.
04-27-2023 05:06 PM
@Raido_Rattameister
Thank you!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!