Use the CLI commands in this section to enable or disable a session log field for each connection event that is logged in to the Network Security appliance to detect SSL interception traffic. You enable the session log separately.
Note
You can enable or disable a session log field only using the CLI. The session log fields are disabled by default.
Prerequisites
Administrator access to the Network Security appliance.
Verify that SSL interception is configured and enabled. For details about how to enable SSL interception, see Enabling or disabling SSL interception using the Web UI or Enabling or disabling SSL interception using the CLI.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Enable each session log field you want to include in the file for SSL interception traffic.
hostname (config) # session-logger ssl field <log_fieldName> enable
where
<log_fieldName>is the log field you want to log to the appliance.Valid session log fields are:
cs_cipher_suite—Cipher suite associated with client-side connections.rs_cipher_suite—Cipher suite associated with server-side connections.rs_cert_status—Server-side certificate that is logged.cs_bytes—Client-side bytes transferred during the connection and logged.rs_bytes—Server-side bytes transferred during the connection and logged.time_taken—Date and time that the connection event is logged.
Verify the status of the session log fields for SSL interception traffic.
hostname (config) # show session-logger ssl config
Example
This example shows how to enable three session log fields for SSL interception traffic.
hostname (config) # session-logger ssl field cs_bytes enable
hostname (config) # session-logger ssl field cs_cipher_suite enable
hostname (config) # session-logger ssl field rs_cipher_suite enable
hostname (config) # show session-logger ssl config Feature Status : enabled Max File Rotation Limit : 5 Field Name : Status ------------------------ cs_bytes : ONcs_cipher_suite : ON rs_bytes : OFF rs_cert_status : OFF rs_cipher_suite : ON time_taken : OFF
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Disable a session log field.
hostname (config) # no session-logger ssl field <log_fieldName> enable
where
<log_fieldName>is the log field you want to log to the appliance.Valid session log fields are:
cs_cipher_suite—Cipher suite associated with client-side connections.
rs_cipher_suite—Cipher suite associated with server-side connections.
rs_cert_status—Server-side certificate that is logged.
cs_bytes—Client-side bytes transferred during the connection and logged. l rs_bytes—Server-side bytes transferred during the connection and logged.
time_taken—Date and time that the connection event is logged.
Verify the status of the session log fields for SSL interception traffic.
hostname (config) # show session-logger ssl config
Example
This example shows how to disable one session log field for SSL interception traffic.
hostname (config) # no session-logger ssl field cs_cipher_suite enable
hostname (config) # show session-logger ssl config Feature Status : enabled Max File Rotation Limit : 5 Field Name : Status ------------------------ cs_bytes : ON cs_cipher_suite : OFF rs_bytes : OFF rs_cert_status : OFF rs_cipher_suite : ON time_taken : OFF