- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-10-2021 04:40 AM - edited 06-14-2021 12:41 PM
I have seen for example on a small firewall when the customer enables SSL decryption that the counters for work groups "ecdhe_key_gen", "flow_host " etc. jump. This may show that the firewall can't handle the ssl decryption or that there is an SSL DDOS attack:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmV2CAK
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXwCAK
If you have access to the Palo Alto Auto Assistant tool (like F5 ihealth but for some reason Palo Alto gives access to this tool only to Partners) you can use it to better view such issue from the Tech support file. Otherwise use the logs and global counters in the articles I provided.
For more about Palo Alto logs and their meaning you can view: