Troubleshoot TLS HEARTBEAT

This task helps you identify TLS HEARTBEAT activity in your network to determine if applications are using the TLS HEARTBEAT extension.

If your managed device has TLS crypto acceleration enabled, you can view connection events to determine whether or not the devices are seeing traffic with the TLS HEARTBEAT extension. You must add at least the SSL Flow Messages event to the table view of connection events.

SSL HEARTBEAT is indicated by the value of HEARTBEAT in the SSL Flow Messages column in the table view of connection events.

Before you begin

To determine if applications in your network use SSL HEARTBEAT, first perform the following tasks:

Follow these steps to troubleshoot TLS heartbeat:

Procedure


Step 1

Click Events & Logs > + Show more > Connection > Events.

Step 2

Click Table View of Connection Events.

Step 3

Click x on any column in the connection events table to add additional columns for at least SSL Flow Flags and SSL Flow Messages.

The image illustrates the addition of various SSL-related columns, including SSL Actual Action, SSL Flow Error, SSL Flow Flags, SSL Flow Messages, SSL Policy, and SSL Rule, to a table of connection events for troubleshooting TLS HEARTBEAT issues.

The following example shows adding the SSL Actual Action, SSL Flow Error, SSL Flow Flags, SSL Flow Messages, SSL Policy, and SSL Rule columns to the table of connection events.

Adding SSL flags to the list of connection events you wish to view.

Step 4

Click Apply.

TLS HEARTBEAT is indicated by the value of HEARTBEAT in the SSL Flow Messages column.

Step 5

If applications in your network use SSL HEARTBEAT, see Decryption Rulesrule-based decryption rules guidelines and limitations.