2.45. SSLINSPECTION

These log messages refer to the SSLINSPECTION category.

2.45.1. [ID: 1460] Abnormal close

Log Categories
SSLINSPECTION
Log Message
Abnormal close.
Default Log Severity
Information
Parameters
sessionid, profile, reason, flow, user, userid
Explanation
The SSL Inspection connection was discovered to be broken.
Gateway Action
Close
Action Description
None
Proposed Action
None

2.45.2. [ID: 1462] Error accepting client connection

Log Categories
SSLINSPECTION
Log Message
Error accepting client connection.
Default Log Severity
Warning
Parameters
sessionid, profile, failure, flow, user, userid
Explanation
An error occurred during initialization of SSL connection with client.
Gateway Action
Reject
Action Description
SSL connection attempt from client was rejected
Proposed Action
None

2.45.3. [ID: 1480] Session allocation failure

Log Categories
SSLINSPECTION
Log Message
Session allocation failure.
Default Log Severity
Critical
Parameters
profile, flow, user, userid
Explanation
Allocating memory to do SSL inspection failed.
Gateway Action
Reject
Action Description
SSL connection attempt from client was rejected
Proposed Action
Change configuration to free up more RAM.

2.45.4. [ID: 1485] Certificate error

Log Categories
SSLINSPECTION
Log Message
Certificate error.
Default Log Severity
Error
Parameters
sessionid, profile, failure, flow, user, userid
Explanation
There was a problem with the certificate.
Gateway Action
Reject
Action Description
None
Proposed Action
Make sure the configured certificate is valid.

2.45.5. [ID: 1495] Client cipher suites mismatch

Log Categories
SSLINSPECTION
Log Message
Client cipher suites mismatch.
Default Log Severity
Notice
Parameters
sessionid, profile, flow, user, userid
Explanation
SSL inspection does not support any of the client's suggested cipher suites.
Gateway Action
Reject
Action Description
SSL connection attempt from client was rejected
Proposed Action
Investigate if additional cipher suites should be enabled.

2.45.6. [ID: 1500] Client TLS version error

Log Categories
SSLINSPECTION
Log Message
Client TLS version error.
Default Log Severity
Notice
Parameters
sessionid, profile, flow, user, userid
Explanation
Client's TLS version is not allowed.
Gateway Action
Reject
Action Description
SSL connection attempt from client was rejected
Proposed Action
Investigate if TLS version of client should be enabled.

2.45.7. [ID: 1466] Error connecting to server

Log Categories
SSLINSPECTION
Log Message
Error connecting to server.
Default Log Severity
Warning
Parameters
sessionid, profile, failure, flow, user, userid
Explanation
An error occurred during initialization of SSL connection with server.
Gateway Action
Reject
Action Description
SSL connection attempt to the server was rejected
Proposed Action
None

2.45.8. [ID: 1498] Flow failed

Log Categories
SSLINSPECTION
Log Message
Flow failed.
Default Log Severity
Warning
Parameters
reason, flow, user, userid
Explanation
Initialization of the TCP connection failed before a SSL Inspection connection was properly initiated.
Gateway Action
Close
Action Description
None
Proposed Action
None

2.45.9. [ID: 1447] Failed to forward SNI

Log Categories
SSLINSPECTION
Log Message
Failed to forward SNI.
Default Log Severity
Warning
Parameters
profile, sni, flow, user, userid
Explanation
The system could not forward the Server Name Indication (SNI) from the client to the protected server. This may cause the SSL connection to the server to fail.
Gateway Action
None
Action Description
None
Proposed Action
None

2.45.10. [ID: 1502] Handshake timeout with

Log Categories
SSLINSPECTION
Log Message
Handshake timeout with.
Default Log Severity
Warning
Parameters
direction, flow, user, userid
Explanation
SSL handshake was taking too long.
Gateway Action
Close
Action Description
None
Proposed Action
None

2.45.11. [ID: 1490] IPS protection closed connection

Log Categories
SSLINSPECTION
Log Message
IPS protection closed connection.
Default Log Severity
Warning
Parameters
sessionid, profile, flow, user, userid
Explanation
IPS detected a problem and decided to close the connection.
Gateway Action
Reject
Action Description
None
Proposed Action
None

2.45.12. [ID: 1474] No server matched SNI

Log Categories
SSLINSPECTION
Log Message
No server matched SNI.
Default Log Severity
Notice
Parameters
profile, sni, flow, user, userid
Explanation
The Server Name Indication (SNI) received from the client did not match any of the configured server patterns.
Gateway Action
None
Action Description
None
Proposed Action
Review the server configuration of the given SSL inspection profile if the problem persists.

2.45.13. [ID: 1483] Error reading data from client

Log Categories
SSLINSPECTION
Log Message
Error reading data from client.
Default Log Severity
Warning
Parameters
sessionid, profile, failure, flow, user, userid
Explanation
An error occurred while trying to read data from the client.
Gateway Action
Reject
Action Description
None
Proposed Action
None

2.45.14. [ID: 1450] Error reading data from server

Log Categories
SSLINSPECTION
Log Message
Error reading data from server.
Default Log Severity
Warning
Parameters
sessionid, profile, failure, flow, user, userid
Explanation
An error occurred while trying to read data from the server.
Gateway Action
Reject
Action Description
None
Proposed Action
None

2.45.15. [ID: 1492] Received SNI from client

Log Categories
SSLINSPECTION
Log Message
Received SNI from client.
Default Log Severity
Information
Parameters
profile, sni, flow, user, userid
Explanation
A client sent a Server Name Indication (SNI) to indicate which host it attempts to connect to.
Gateway Action
None
Action Description
None
Proposed Action
None

2.45.16. [ID: 1484] Server cipher suites mismatch

Log Categories
SSLINSPECTION
Log Message
Server cipher suites mismatch.
Default Log Severity
Notice
Parameters
sessionid, profile, flow, user, userid
Explanation
SSL inspection does not support any of the server's suggested cipher suites.
Gateway Action
Reject
Action Description
SSL connection attempt to the server was rejected
Proposed Action
Investigate if additional cipher suites should be enabled.

2.45.17. [ID: 1481] Server TLS version error

Log Categories
SSLINSPECTION
Log Message
Server TLS version error.
Default Log Severity
Notice
Parameters
sessionid, profile, flow, user, userid
Explanation
Server's TLS version is not allowed.
Gateway Action
Reject
Action Description
SSL connection attempt to server was rejected
Proposed Action
Investigate if TLS version of server should be enabled.

2.45.18. [ID: 1487] Session closed

Log Categories
SSLINSPECTION
Log Message
Session closed.
Default Log Severity
Information
Parameters
sessionid, profile, flow, user, userid
Explanation
None
Gateway Action
Close
Action Description
None
Proposed Action
None

2.45.19. [ID: 1456] Connection established

Log Categories
SSLINSPECTION
Log Message
Connection established.
Default Log Severity
Information
Parameters
sessionid, profile, type, clienttlsver, clientcipher, servertlsver, servercipher, flow, user, userid
Explanation
SSL connection successfully established.
Gateway Action
Open
Action Description
None
Proposed Action
None

2.45.20. [ID: 1494] Session opened

Log Categories
SSLINSPECTION
Log Message
Session opened.
Default Log Severity
Information
Parameters
sessionid, profile, flow, user, userid
Explanation
A connection has been initiated.
Gateway Action
Open
Action Description
None
Proposed Action
None

2.45.21. [ID: 1444] Error writing data to client

Log Categories
SSLINSPECTION
Log Message
Error writing data to client.
Default Log Severity
Warning
Parameters
sessionid, profile, failure, flow, user, userid
Explanation
An error occurred while trying to write data to the client.
Gateway Action
Reject
Action Description
None
Proposed Action
None

2.45.22. [ID: 1499] Error writing data to client

Log Categories
SSLINSPECTION
Log Message
Error writing data to client.
Default Log Severity
Warning
Parameters
sessionid, profile, failure, flow, user, userid
Explanation
An error occurred while trying to write data to the server.
Gateway Action
Reject
Action Description
None
Proposed Action
None