<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL inspection with FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssl-inspection-with-fmc/m-p/4004848#M934435</link>
    <description>&lt;P&gt;ASA 5515x's with two 100mb shared connections&lt;/P&gt;</description>
    <pubDate>Mon, 30 Dec 2019 17:23:12 GMT</pubDate>
    <dc:creator>ethutchinson</dc:creator>
    <dc:date>2019-12-30T17:23:12Z</dc:date>
    <item>
      <title>SSL inspection with FMC</title>
      <link>https://community.cisco.com/t5/network-security/ssl-inspection-with-fmc/m-p/4004842#M934433</link>
      <description>&lt;P&gt;I found out recently my FMC's&amp;nbsp; (6.4.0.4) URL filter was not catching HTTPS traffic (My Bad), So I started researching how to do this. I have downloaded the cert from my CA and I was about to install it and setup the SSL policy. Before I do this can I get some advantages (obvious) and disadvantages (performance?) to doing this? I know it looks pretty obvious but I wanted to know if I am missing something in my planning. I guess one of my major fears/concerns would be blocking a good site either internally or externally accessed. We have about 500 desktops and if I am going to wreck their days I want to know ahead of time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-inspection-with-fmc/m-p/4004842#M934433</guid>
      <dc:creator>ethutchinson</dc:creator>
      <dc:date>2020-02-21T17:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inspection with FMC</title>
      <link>https://community.cisco.com/t5/network-security/ssl-inspection-with-fmc/m-p/4004846#M934434</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The advantages to using SSL decryption is being able to determine what sites are being accessed and denying access - this could be malicious traffic, which you'd want to block. You are correct, enabling SSL decryption would have an impact on performance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What hardware are you using?&lt;/P&gt;
&lt;P&gt;And what is the bandwidth of your internet connection?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 17:19:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-inspection-with-fmc/m-p/4004846#M934434</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-12-30T17:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inspection with FMC</title>
      <link>https://community.cisco.com/t5/network-security/ssl-inspection-with-fmc/m-p/4004848#M934435</link>
      <description>&lt;P&gt;ASA 5515x's with two 100mb shared connections&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 17:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-inspection-with-fmc/m-p/4004848#M934435</guid>
      <dc:creator>ethutchinson</dc:creator>
      <dc:date>2019-12-30T17:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inspection with FMC</title>
      <link>https://community.cisco.com/t5/network-security/ssl-inspection-with-fmc/m-p/4004850#M934436</link>
      <description>&lt;P&gt;The screenshot below is from the Firepower Performance Estimator, set at 100Mb bandwidth with only the Base and SSL Decryption features enabled. The output indicates the performance of the different ASA models, except the 5515X so cannot estimate what the impact will be.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/64247i01A229FB35D029B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 17:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-inspection-with-fmc/m-p/4004850#M934436</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-12-30T17:46:18Z</dc:date>
    </item>
  </channel>
</rss>

