Troubleshoot TLS/SSL oversubscription
Monitor and troubleshoot TLS/SSL oversubscription by configuring decryption policies, enabling logging, and adding SSL Flow Flags to connection event views in Cloud-Delivered Firewall Management Center.
If your managed device has TLS crypto acceleration enabled, you can view connection events to determine whether or not the devices are experiencing SSL oversubscription. You must add at least the SSL Flow Flags event to the table view of connection events.
Before you begin
-
Configure a decryption policy with a setting for Handshake Errors on Undecryptable Actions page.
For more information, see Set default handling for undecryptable traffic.
-
Enable logging for your SSL rules as discussed in the section on logging decryptable connections in decryption rules in the Secure Firewall Management Center and Threat Defense Management Network Administration guide.
Follow these steps to troubleshoot TLS/SSL oversubscription:
Procedure
Step 1 | Click | ||||||
Step 2 | Click the colum picker ( | ||||||
Step 3 | Click Apply. TLS/SSL oversubscription is indicated by the values of ERROR_EVENT_TRIGGERED and OVER_SUBSCRIBED in the SSL Flow Flags column. | ||||||
Step 4 | If TLS/SSL oversubscription is occurring, log in to the managed device and enter any of the following commands:
|
