SSLV - TLS_SESSION:Heartbleed attack from client
search cancel

SSLV - TLS_SESSION:Heartbleed attack from client

book

Article ID: 400234

calendar_today

Updated On:

Products

SV3800 SSL Visibility Appliance Software

Issue/Introduction

Inspection Error Counts on SSLv indicates Heartbleed attack from client. The KB indicates how to get more details of clients who sends malformed TLS packets.

Resolution

When SSLv detects Heartbleed attack, it will log the error in SSL session log, Increase counter and reject the session. 

Transaction details can be found in the session logs. Error counts are cleared when changes are made to the current ruleset, and policy is reset.

It means session logs should be filtered since the last changes to the current rule set.