This CLI command displays SSL decryption statistics for the Sensor.
SSL decryption is enabled in one direction at a given point of time. The command displays SSL statistics for the direction in which the decryption is enabled.
Syntax:
show ssl stats <inbound|outbound>
Applicable to:
NS-series Sensors
Inbound SSL Decryption
When SSL decryption is enabled only for RSA ciphers, the following information is displayed:
- The names of any certificates loaded into the Manager, and how many times they have been used in sessions since the Sensor was last rebooted.
- The number of certificates passed for which the Sensor had no matching certificates
When SSL decryption is enabled for DHE/ECDHE ciphers that includes RSA ciphers as well, the following information is displayed:
- Number of SSL records processed by the Sensor
- Number of matched shared SSL keys
- Number of Active SSL Agent connections for IPv4 and IPv6 IP addresses
Syntax:
show ssl stats inbound known-key
Sample output:
No Certs are present
[Certs Matched]
Number of certs Mismatched : 822
Number of SSL records processed by SSL module : 4998793
Matched SSL Shared Keys : 12
Total SSL Shared Keys : 79
Active SSL Agent connections(v4) : 81
Active SSL Agent connections(v6) : 0
Total SSL Agent connections(v4) : 87
Total SSL Agent connections(v6) : 0
Applicable to:
When using only RSA ciphers: NS-series Sensors
When using DHE/ECDHE ciphers: NS9500, NS9x00, NS7500, NS7x00 and NS5x00 series Sensors
When SSL decryption is enabled using proxy, the following information is displayed:
- Name of the Certificate
- Number of times the certificate was used
- Number of times decryption was bypassed
Syntax:
show ssl stats inbound proxy <cpu|exceptions|port|sessions|sslinfo|status>
| Parameter | Description |
|---|---|
| cpu | Displays the CPU utilization for the last 1, 4, and 64 seconds |
| port | Displays the statistics for the configured VLAN ports |
| sessions | Displays the number of sessions per port |
| sslinfo | Displays the statistics for the SSL connection, such as handshake, session information, and so on |
| status | Displays if SSL decryption is configured and enabled |
Sample output:
intruShell@john-9500> show ssl stats inbound proxy status
Decryption configured: yes
Decryption enabled: yes
Decryption engine ready: yes
Engine provisioning status: (requested=yes ; done=yes)
Applicable to:
NS9500 and NS7500 Sensors only
Outbound SSL Decryption
The command displays the following information when outbound SSL decryption is enabled:
| Parameter | Description |
|---|---|
| cpu | Displays the CPU utilization for the last 1, 4, and 64 seconds |
| exceptions | Displays the status for the exceptions added to the URL allow list |
| port | Displays the statistics for the configured VLAN ports |
| sessions | Displays the number of sessions per port |
| sslinfo | Displays the statistics for the SSL connection, such as handshake, session information, and so on |
| status | Displays if SSL decryption is configured and enabled |
Syntax:
show ssl stats outbound proxy <cpu|exceptions|port|sessions|sslinfo|status>
Sample output:
intruShell@Perf_7200> show ssl stats outbound proxy status
Decryption configured: yes
Decryption enabled: yes
Decryption engine ready: yes
Engine provisioning status: (requested=yes ; done=yes)
Applicable to:
NS9500, NS9100, NS9200, NS7500, NS7300, and NS7200 Sensors