This CLI command displays SSL decryption statistics for the Sensor.
SSL decryption is enabled in one direction at a given point of time. The command displays SSL statistics for the direction in which the decryption is enabled.
Syntax:
show ssl stats <inbound|outbound>
Applicable to:
NS-series Sensors
Inbound SSL Decryption
When SSL decryption is enabled only for RSA ciphers, the following information is displayed:
The names of any certificates loaded into the Manager, and how many times they have been used in sessions since the Sensor was last rebooted.
The number of certificates passed for which the Sensor had no matching certificates
When SSL decryption is enabled for DHE/ECDHE ciphers that includes RSA ciphers as well, the following information is displayed:
Number of SSL records processed by the Sensor
Number of matched shared SSL keys
Number of Active SSL Agent connections for IPv4 and IPv6 IP addresses
Syntax:
show ssl stats inbound known-key
Sample output:
No Certs are present
[Certs Matched]
Number of certs Mismatched : 822
Number of SSL records processed by SSL module : 4998793
Matched SSL Shared Keys : 12
Total SSL Shared Keys : 79
Active SSL Agent connections(v4) : 81
Active SSL Agent connections(v6) : 0
Total SSL Agent connections(v4) : 87
Total SSL Agent connections(v6) : 0
Applicable to:
When using only RSA ciphers: NS-series Sensors
When using DHE/ECDHE ciphers: NS9600, NS9500, NS9x00, NS7600, NS7500, NS7x00, NS5x00, and NS3600 series Sensors
When SSL decryption is enabled using proxy, the following information is displayed:
Name of the Certificate
Number of times the certificate was used
Number of times decryption was bypassed
Syntax:
show ssl stats inbound proxy <cpu|exceptions|port|sessions|sslinfo|status>
Parameter | Description |
|---|---|
| Displays the CPU utilization for the last 1, 4, and 64 seconds |
| Displays the statistics for the configured VLAN ports |
| Displays the number of sessions per port |
| Displays the statistics for the SSL connection, such as handshake, session information, and so on |
| Displays if SSL decryption is configured and enabled |
Sample output:
intruShell@john-9500> show ssl stats inbound proxy status
Decryption configured: yes
Decryption enabled: yes
Decryption engine ready: yes
Engine provisioning status: (requested=yes ; done=yes)
Applicable to:
NS9500 and NS7500 Sensors only
Outbound SSL Decryption
The command displays the following information when outbound SSL decryption is enabled:
Parameter | Description |
|---|---|
| Displays the CPU utilization for the last 1, 4, and 64 seconds |
| Displays the status for the exceptions added to the URL allow list |
| Displays the statistics for the configured VLAN ports |
| Displays the number of sessions per port |
| Displays the statistics for the SSL connection, such as handshake, session information, and so on |
| Displays if SSL decryption is configured and enabled |
Syntax:
show ssl stats outbound proxy <cpu|exceptions|port|sessions|sslinfo|status>
Sample output:
intruShell@Perf_7200> show ssl stats outbound proxy status
Decryption configured: yes
Decryption enabled: yes
Decryption engine ready: yes
Engine provisioning status: (requested=yes ; done=yes)
Applicable to:
NS9500, NS9100, NS9200, NS7500, NS7300, and NS7200 Sensors