Displays the connection event log details about traffic from the SSL flows that are actively inspected or not inspected.
For details about how to display the connection event logs, see the "Managing the Connection Event Logs of the SSL Flows" section in the "Troubleshooting" appendix of the Network Security User Guide.
Syntax
show session-logger ssl
Parameters
None
Output fields
The following table describes the output fields for the show session-logger ssl command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Date | Date that the connection event is logged. |
Time | Time that the connection event is logged. |
c_ip | IP address of the client. |
c_port | Port number of the client. |
s_ip | IP address of the server. |
s_port | Port number of the server. |
cs_bytes | Client-side bytes transferred during the connection and logged. |
rs_bytes | Server-side bytes transferred during the connection and logged. |
cs_tls_ version | TLS version required for client-side connections. |
rs_tls_ version | TLS version required for server-side connections. |
cs_cipher_ suite | Cipher suite associated with client-side connections. |
rs_cipher_ suite | Cipher suite associated with server-side connections. |
rs_cert_ common_ name | Common name of the server-side certificate. |
action | Whether the connection was decrypted, whitelisted, or blocked due to an attack seen in decrypted content. |
s_site_name | Server name identification (SNI) sent by the client or server. |
error | Types of error codes for connection events:
|
Example
The following example displays partial output of the connection event log details:
hostname # show session-logger ssl ........ Oct 12 17:38:21 192.168.69.157 52532 34.208.13.0 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:TLSv1.2 cs_cipher_suite:N/A rs_cipher_suite:ECDHE-RSA-AES128-SHA rs_cert_common_name:1493776677490-670-sfs.crt.uid action:(ssl-1,whitelisted-0,block-0) s_site_name:sfPKI/F88A1AD9 error:(error -Protocol error 71,ssl_error -tlsv1 alert unknown ca 336151576) Oct 12 17:38:43 192.168.69.157 52534 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568) Oct 12 17:39:43 192.168.69.157 52535 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568) Oct 12 17:40:15 192.168.69.157 52538 34.208.13.0 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:TLSv1.2 cs_cipher_suite:N/A rs_cipher_suite:ECDHE-RSA-AES128-SHA rs_cert_common_name:1493776677490-670-sfs.crt.uid action:(ssl-1,whitelisted-0,block-0) s_site_name:sfPKI/F88A1AD9 error:(error -Protocol error 71,ssl_error -tlsv1 alert unknown ca 336151576) Oct 12 17:40:00 192.168.69.157 52537 10.35.30.248 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:bitlocker.fireeye.com error:N/A ........
User role
Admin
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 8.2.1.