Use the CLI commands in this section to view details about live traffic from the SSL flows that matches or does not match a particular attribute in the current log file. Viewing all of the live log details on SSL flows can help you to identify the most recent trends or patterns in SSL Network Security SSL Session Log module on the Network Security appliance, see Viewing the Connection Event Logs.
Note
The archived logs are not displayed in the current log file.
Log in to the appliance CLI and go to enable mode.
hostname > enable
View all the new logs as they arrive on the Network Security appliance.
hostname # show session-log ssl continuous
Log in to the appliance CLI and go to enable mode.
hostname > enable
View the live traffic details about SSL flows that matched a particular attribute in the current log file.
hostname # show session-logger ssl continuous matching <value>
where
<value>can be a particular date and time, domain name, client IP address and port, server IP address and port, cipher suite, SNI sent by the client or server, and action that was taken on the SSL flow.View the live traffic details about SSL flows that did not match a particular attribute in the current log file.
hostname # show session-logger ssl continuous not matching <value>
where
<value>can be a particular date and time, domain name, client IP address and port, server IP address and port, cipher suite, SNI sent by the client or server, and action that was taken on the SSL flow.
Examples
This example displays partial output about live traffic as it arrived on the Network Security appliance.
hostname # show session-log ssl continuous ........ Oct 12 20:05:21 192.168.69.157 53748 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568) Oct 12 20:05:00 192.168.69.157 53747 10.35.30.248 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:bitlocker.fireeye.com error:N/A Oct 12 20:05:30 192.168.69.157 53749 10.35.30.248 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:bitlocker.fireeye.com error:N/A Oct 12 20:06:22 192.168.69.157 53751 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568) Oct 12 20:07:22 192.168.69.157 53753 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568) Oct 12 20:08:22 192.168.69.157 53754 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568) ........
This example displays partial output about live traffic that matched a server IP address as it arrived on the Network Security appliance.
hostname # show session-logger ssl continuous matching 10.35.30.248 Oct 12 20:05:00 192.168.69.157 53747 10.35.30.248 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl- 1,whitelisted-0,block-0) s_site_name:bitlocker.fireeye.com error:N/A Oct 12 20:05:30 192.168.69.157 53749 10.35.30.248 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl- 1,whitelisted-0,block-0) s_site_name:bitlocker.fireeye.com error:N/A ........
This example displays partial output about live traffic that did not match the cipher suite as it arrived on the Network Security appliance.
hostname # show session-log ssl continuous not matching ECDHE-RSA-AES128-GCM-SHA256 Oct 02 01:13:01 192.168.69.157 62878 54.209.82.95 443 cs_bytes:N/A cs_tls_version:TLSv1.2 rs_tls_version:TLSv1.2 cs_cipher_suite:(NONE) rs_cipher_suite:ECDHE-RSA-AES256-GCM-SHA384 rs_cert_common_name:jobserver action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:N/A Oct 02 01:13:14 192.168.69.157 62882 72.21.81.200 443 cs_bytes:N/A cs_tls_version:TLSv1.2 rs_tls_version:TLSv1.2 cs_cipher_suite:(NONE) rs_cipher_suite:ECDHE-RSA-AES256-GCM-SHA384 rs_cert_common_name:*.vo.msecnd.net action:(ssl-1,whitelisted-0,block-0) s_site_name:onecs-live.azureedge.net error:N/A Oct 02 01:13:33 192.168.69.157 62887 72.21.81.200 443 cs_bytes:N/A cs_tls_version:TLSv1.2 rs_tls_version:TLSv1.2 cs_cipher_suite:(NONE) rs_cipher_suite:ECDHE-RSA-AES256-GCM-SHA384 rs_cert_common_name:*.vo.msecnd.net action:(ssl-1,whitelisted-0,block-0) s_site_name:onecs- live.azureedge.net error:N/A ........