Handshake buffer allocation failures are seen with SSL traffic in NS-Series 9100 and IPS-VM600 Sensors
Last Modified: 2024-01-22 11:27:01 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
Handshake buffer allocation failures are seen with SSL traffic in NS-Series 9100 and IPS-VM600 Sensors
Technical Articles ID:
KB96096
Last Modified: 2024-01-22 11:27:01 Etc/GMT Environment
Trellix Intrusion Prevention System (Trellix IPS)
Problem
NS-Series 9100 or IPS-VM600 Sensors show handshake buffer allocation failures on SSL traffic (Extended Cause
To support the SSL EMS extension according to RFC 7627, the Sensor reserves a specific amount of system memory. This reservation is to track handshake messages, while computing the master key, for the decryption of SSL traffic. Current system memory allocation:
Solution
The messages relate to handshake buffer allocation failures with SSL traffic in the log entries. They don't indicate that the Sensor stops the SSL traffic inspection completely. You temporarily see these failures when the Sensor can't decrypt the new SSL flows, for a few milliseconds. But, the Sensor continues the inspection for decrypted SSL flows. When buffers are available, the Sensor resumes decryption of new SSL flows. Affected ProductsLanguages:This article is available in the following languages: |
|