SSL Decryption Session is Full

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

SSL Decryption Session is Full

L3 Networker

Hello all, 

 

When the SSL Decryption Session is full, the customer asks how the non-decryption traffic is handled.

We need information about whether the lack of resources is causing random drops or not being affected.

The current model is VM-700, VM-300 and the OS is 9.1.14. CPU and Memory are set to Allow maximum.

Kind regards,

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

If you are performing decryption then it depends on how decryption profile is configured.

Objects > Decryption > Decryption Profile

"Block sessions if resources not available"

 

If checkbox is not checked then sessions will pass through but won't be decrypted.

If checked then additional sessions won't be allowed.

Imagine someone wanting to get out your network bypassing decryption it is possible to initiate loads of ssl sessions until firewall starts bypassing new sessions without decryption.

 

 

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

If you are performing decryption then it depends on how decryption profile is configured.

Objects > Decryption > Decryption Profile

"Block sessions if resources not available"

 

If checkbox is not checked then sessions will pass through but won't be decrypted.

If checked then additional sessions won't be allowed.

Imagine someone wanting to get out your network bypassing decryption it is possible to initiate loads of ssl sessions until firewall starts bypassing new sessions without decryption.

 

 

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

@Raido_Rattameister 

Thank you!

  • 1 accepted solution
  • 1992 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!