Use the CLI commands in this section to view connection event log details about traffic from the SSL flows that are being actively inspected or not inspected. For a description of each log field generated by the SSL Session Log module on the appliance, see Viewing the Connection Event Logs.
Log in to the appliance CLI and go to enable mode.
hostname > enable
View the log details about SSL interception traffic.
hostname # show session-logger ssl
The following example displays partial output of the connection event log details:
hostname # show session-logger ssl ........ Oct 12 17:38:21 192.168.69.157 52532 34.208.13.0 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:TLSv1.2 cs_cipher_suite:N/A rs_cipher_suite:ECDHE-RSA-AES128-SHA rs_cert_common_name:1493776677490-670-sfs.crt.uid action:(ssl-1,whitelisted-0,block-0) s_site_name:sfPKI/F88A1AD9 error:(error -Protocol error 71,ssl_error -tlsv1 alert unknown ca 336151576) Oct 12 17:38:43 192.168.69.157 52534 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568) Oct 12 17:39:43 192.168.69.157 52535 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568) Oct 12 17:40:15 192.168.69.157 52538 34.208.13.0 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:TLSv1.2 cs_cipher_suite:N/A rs_cipher_suite:ECDHE-RSA-AES128-SHA rs_cert_common_name:1493776677490-670-sfs.crt.uid action:(ssl-1,whitelisted-0,block-0) s_site_name:sfPKI/F88A1AD9 error:(error -Protocol error 71,ssl_error -tlsv1 alert unknown ca 336151576) Oct 12 17:40:00 192.168.69.157 52537 10.35.30.248 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:bitlocker.fireeye.com error:N/A ........