Configuring Ssl Decryption In The Ips Sensor - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
For a description of SSL functionality in Network Security Platform, see the
Guide
The available actions in this group are:
Figure 204: SSL Decryption Tab

Configuring SSL decryption in the IPS Sensor

The
configuration includes enabling SSL decryption, enabling packet logging for SSL-
encrypted attacks, setting the number of SSL flows to monitor simultaneously, and setting
the session cache time.
The number of supported SSL flows on a Sensor directly impacts the number of TCP flows
that can be processed simultaneously by a 2-to-1 ratio. For example, an I-4000 Sensor
can maintain 1,000,000 TCP flows. When you set the number of SSL flows (
to 100,000 (the maximum), that value reduces the number of TCP flows monitored by an I-
4000 to 800,000 flows.
Note 1:
Note 2:
be rebooted. Also, if the SSL Flow Count is changed, a Sensor reboot is required.
To enable and configure SSL decryption on a Sensor, do the following:
1
2
3
4
.
Configuring the SSL functionality of a Sensor (on page 205): Enable SSL decryption
and configure Sensor SSL parameters.
Managing the imported SSL keys of a Sensor (on page 206): Manage the SSL keys
that have been imported to Manager for the selected Sensor.
Importing SSL keys to Manager for a Sensor (on page 206): Import SSL keys to
Manager for download to a Sensor for SSL traffic decryption.
SSL Decryption > Enable
action enables the SSL functionality of a Sensor. SSL
SSL decryption is not supported on I-1200, I-1400, M-series Sensors.
In order to enable/disable SSL functionality on a Sensor, the Sensor must
Sensor_Name > SSL Decryption > Enable
Click
the case of a failover pair).
Yes
SSL Enabled
Click
at
to enable SSL decryption on the Sensor.
Yes
Enable Logging of Decrypted Packets in the Packet Log
Click
at
for attacks that contain decrypted SSL-protected data.
Note:
A packet log for an SSL encrypted attack displays, that is, decrypts, the
data related to the attack.
SSL Flow Count
Enter an
value. This value represents the number of SSL flows that can
be processed at a given time by a Sensor. The value range is Sensor specific: for I-
4000, the range is 100-100000.
Note:
The number of supported SSL flows on a Sensor directly impacts the
number of TCP flows that can be processed simultaneously.
Failover pair Name > SSL Decryption > Enable
or
205
The IPS Sensor_Name node
Getting Started
SSL Flow Count
(in
to enable packet logging
)

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents