Troubleshoot TLS heartbeat

This task helps you identify TLS heartbeat activity in your network to determine if applications are using the TLS heartbeat extension.

If your managed device has TLS crypto acceleration enabled, you can view connection events to determine whether or not the devices are seeing traffic with the TLS heartbeat extension. You must add at least the SSL Flow Messages event to the table view of connection events.

TLS heartbeat is indicated by the value of HEARTBEAT in the SSL Flow Messages column in the table view of connection events.

Before you begin

To determine if applications in your network use TLS heartbeat, first perform these tasks:

Follow these steps to troubleshoot TLS heartbeat:

Procedure


Step 1

Click Events & Logs > Analysis > Unified Events

Step 2

Click the colum picker (column picker icon) icon and add additional columns TLS Flow Flags and TLS Flow Messages.

Step 3

Click Apply.

TLS heartbeat is indicated by the value of HEARTBEAT in the SSL Flow Messages column.

Step 4

If applications in your network use TLS heartbeat, refer to Decryption RulesRule-based decryption rules guidelines and limitations.