Show Local Exclusion Cache | Show Local Exclusion Cache displays sites that the firewall automatically
excluded from decryption due to technical issues that prevent
decryption, such as pinned certificates, client authentication, or
unsupported ciphers. Each cache entry includes information about the
application, the server, the reason the firewall excluded the site
from decryption, the decryption profile applied to the traffic, and
the virtual system (vsys). The firewall populates the Local SSL Decryption Cache with locally discovered decryption
exceptions, based on the settings of the decryption profile
associated with the decryption policy rule that controls the
traffic. Sites remain in the local cache for 12 hours and then age
out.
The Local SSL Decryption Cache differs from the SSL Decryption
Exclusion List (DeviceCertificate
ManagementSSL Decryption
Exclusion). The SSL Decryption Exclusion List is for
more permanent exclusions. It contains predefined sites identified
by Palo Alto Networks as preventing decryption and exclusions you
choose to add. |