- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: HTTPS Inspection logs rotation
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HTTPS Inspection logs rotation
Hello dear experts.
We are trying collect information about used version of encryption protocols like as ssl/tls using debug for WSTLSD (sk105559).
But debug allows you to save log files with a maximum of 20 MB and no more than 9 pieces. Is it possible to increase the size of debug files and their number?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The debug logs were not meant to be run long term like this.
Is this information not in the regular access logs?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello.
Yes, information about used encryption protocols and cipher suite collected only if we make debug for WSTLSD.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello! If you know another method how to collect information about used encryption protocols and cipher suite, please share....
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good evening.
I will try to describe our task in more detail. Our infrastructure has a fairly large number of web services available through https. We would like to disable legacy encryption protocols and cipher suites, but we are not sure if all clients will be able to continue using these services. Therefore, we would like to first collect statistics on the used encryption protocols and cipher suites. And since we use SSL inspection on the checkpoint gateway, we want to collect this information on the gateway. Maybe you know how else we can collect this information other than when debugging the wstlsd.
