If you want the firewall to block SSL/TLS sessions when
the OCSP or CRL service returns a certificate revocation status
of unknown, select the
Block Session With Unknown Certificate
Status
check box. Otherwise, the firewall proceeds with
the session.