Loading...
Loading...
TLS Server Identify feature was introduced in 6.7 release to handle TLS 1.3 server certificate information. If the certificate is not found, the TLS connection is paused, and the firewall (Lina engine) initiates a new TLS 1.2 connection request to the target server in order to obtain its unencrypted certificate. This connection is referred to as the "Probe" connection. It is terminated once the certificate is obtained. The problem is that these probes are seen in the 'show asp table socket' output and can generate thousands of entries: FTD3110-7# show asp table socket Protocol Socket State Local Address Foreign Address TLS_TRK 109fae08 ESTAB 192.0.2.1:443 192.0.2.200:20716 TLS_TRK 109fae15 ESTAB 192.0.2.1:443 192.0.2.210:21345 TLS_TRK 109fac86 ESTAB 192.0.2.1:443 192.0.2.220:20782 ... This can make the 'show tech-support' output tens of times larger.
- TLS Server Identity feature is enabled - The firewall is handling TLS 1.3 traffic
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.