show session-logger ssl continuous

Prev Next

Displays all of the live log details on SSL flows that can help you to identify the most recent trends or patterns in SSL interception traffic as they arrive on the Network Security appliance.

For details about how to display the live traffic log file details, see the "Managing the Connection Event Logs of the SSL Flows" section in the "Troubleshooting" appendix of the Network Security User Guide.

Syntax

show session-logger ssl continuous

Parameters

None

Output fields

The following table describes the output fields for the show session-log ssl continuous command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Date

Date that the connection event is logged.

Time

Time that the connection event is logged.

c_ip

IP address of the client.

c_port

Port number of the client.

s_ip

IP address of the server.

s_port

Port number of the server.

cs_bytes

Client-side bytes transferred during the connection and logged.

rs_bytes

Server-side bytes transferred during the connection and logged.

cs_tls_ version

TLS version required for client-side connections.

rs_tls_ version

TLS version required for server-side connections.

cs_cipher_ suite

Cipher suite associated with client-side connections.

rs_cipher_ suite

Cipher suite associated with server-side connections.

rs_cert_ common_ name

Common name of the server-side certificate.

action

Whether the connection was decrypted, whitelisted, or blocked due to an attack seen in decrypted content.

s_site_name

Server name identification (SNI) sent by the client or server.

error

Types of error codes for connection events:

  • 71 Protocol Error—For example, the requested URL could not be retrieved.

  • sslv3 alert handshake failure—For example, server certificate expired or an incorrect certificate was configured.

Example

The following example displays partial output about live traffic as it arrived on the Network Security appliance.

hostname # show session-log ssl continuous
........
  Oct 12 20:05:21 192.168.69.157 53748 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568)
  Oct 12 20:05:00 192.168.69.157 53747 10.35.30.248 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:bitlocker.fireeye.com error:N/A
  Oct 12 20:05:30 192.168.69.157 53749 10.35.30.248 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:bitlocker.fireeye.com error:N/A
  Oct 12 20:06:22 192.168.69.157 53751 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568)
  Oct 12 20:07:22 192.168.69.157 53753 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568)
  Oct 12 20:08:22 192.168.69.157 53754 54.209.82.95 443 cs_bytes:N/A cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-0,block-0) s_site_name:N/A error:(error -Protocol error 71,ssl_error -sslv3 alert handshake failure 336151568)
........

User role

Administrator

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.2.1.