Following are a few limitations when using the outbound SSL decryption feature:
Decryption of VLAN tagged packets is not supported in NS9300, NS9200, NS9100, NS7350, NS7250, NS7150, NS7300, NS7200, NS7100, NS5200, NS5100, NS3500, NS3200, and NS3100 Sensor models.
Decryption of double VLAN tagged packets is not supported in NS9300, NS9200, NS9100, NS7350, NS7250, NS7150, NS7300, NS7200, NS7100, NS5200, NS5100, NS3500, NS3200, and NS3100 Sensor models.
Only SSL HTTP traffic on port 443 is decrypted.
If the Sensor performing decryption fails, all the sessions timeout and you have to recreate the session manually.
Failover is not supported for outbound SSL decryption as the session keys are always available in the active Sensor only. The session keys are not synchronized to the passive Sensor.
Traffic statistics and performance charts are not supported for outbound SSL decryption.