|
Show Local Exclusion Cache
|
Show Local Exclusion Cache displays sites that
the firewall automatically excluded from decryption due to technical
issues that prevent decryption, such as pinned certificates, client
authentication, or unsupported ciphers. Each cache entry includes
information about the application, the server, the reason the
firewall excluded the site from decryption, the decryption profile
applied to the traffic, and the virtual system (vsys).
The firewall populates the Local SSL Decryption Cache with locally
discovered decryption exceptions, based on the settings of the
decryption profile associated with the decryption policy rule that
controls the traffic. Sites remain in the local cache for 12 hours
and then age out.
The Local SSL Decryption Cache differs from the SSL Decryption
Exclusion List (DeviceCertificate
ManagementSSL Decryption
Exclusion). The SSL Decryption Exclusion List is for
more permanent exclusions. It contains predefined sites identified
by Palo Alto Networks as preventing decryption and exclusions you
choose to add.
|