Jump to content

Recommended Posts

Posted

Hi all,

 

We use Websense as our main proxy and have recently noticed some performance issues (particularly with uploads to Google drive and other services).

 

SSL interception is enabled (which means that all SSL encrypted traffic is decrypted, scanned/filtered and re-encrypted). Post Snowden, an increasing proportion of sites are SSL enabled (e.g. practically all Google services it seems), so I am wondering what kind of impact this extra processing burden is having on our proxy (and our end user experience).

 

Our Internet connection is 1Gbit. We recently measured file upload performance to Google drive and it came in at 20Mbit, which is acceptable for small files, but is not for large files (e.g. 1GB videos). Without Websense (or using Bloxx as a proxy, which doesn't intercept SSL) the throughput was a more respectable 120Mbit.

 

We don't yet know if SSL interception is the culprit or it is caused by some other aspect of the way Websense is configured or functions (further testing is required).

 

But my question is, has anyone else experienced poor upload throughput using Websense and what was the cause/solution?

 

Has anyone noticed any proxy performance issues which relate to the processing of (the increasing amount of) SSL traffic (where interception is enabled)?

 

Yes, I know not everyone agrees with SSL interception, but there is a strong case for it here in relation to Safeguarding.

 

Thank you,

 

Bruce.

Posted

Can't help with Websense specifically but I've not seen a single service/appliance/server that doesn't take a hit when SSL intercept is invoked most start to slow down just with DPI turned on.

So much so firewalls we specified 3-5 yrs ago that were "more than adequate for the foreseeable future" simply don't come close to the current and ever increasing demands placed on them by schools.

 

As a result where a £3k solution for a secondary was fine 3yrs ago £10-12k to replace one now seems quite acceptable!

 

I suspect with ever increasing demands for tighter control on activity monitoring in schools budgets are going to take battering as more powerful and sophisticated hardware is needed at the gateways to combat the threats of network intrusions and the fight against radicalisation etc of users becomes an expected task of the schools themselves.

Posted

indeed any ssl interception is going to increase proxy load and as more and more sites switch to ssl your proxy will be doing more.

 

What are the proxys running on virtualised hardward or a v5k or v10k appliance?

 

Ben

  • 2 weeks later...
Posted
indeed any ssl interception is going to increase proxy load and as more and more sites switch to ssl your proxy will be doing more.

 

What are the proxys running on virtualised hardward or a v5k or v10k appliance?

 

Ben

 

v10k. Further testing by ourselves and Websense support show that the issue doesn't relate to either SSL Interception or filtering (as these have been disabled - enabled SSL tunnelling - and the issue is exactly the same).

 

This issue also occurs on our other two Websense v10K boxes. However, Websense support could not replicate the problem on in their lab.

 

This is increasingly becoming issue as we are adopting Google cloud storage.

 

Thanks,

 

Bruce.

Posted
So much so firewalls we specified 3-5 yrs ago that were "more than adequate for the foreseeable future" simply don't come close to the current and ever increasing demands placed on them by schools.

 

Just to throw my 2p in here - this is one of the reasons why a few months ago we moved our Smoothwall to a virtual machine from physical hosts. With SSL inspection turned on I'm starting to see a rise in CPU usage and we just wouldn't have the funds to fork out for new hardware that often.

Posted
v10k. Further testing by ourselves and Websense support show that the issue doesn't relate to either SSL Interception or filtering (as these have been disabled - enabled SSL tunnelling - and the issue is exactly the same).

 

This issue also occurs on our other two Websense v10K boxes. However, Websense support could not replicate the problem on in their lab.

 

This is increasingly becoming issue as we are adopting Google cloud storage.

 

Thanks,

 

Bruce.

 

Interesting as the V10 appliances are some seriously nice boxes especially if they are only running web and not email or dlp as well.

 

What version of Websense are you on?

 

Ben

  • 4 weeks later...
Posted

Decrypting SSL is expensive in CPU time, especially as were are seeing more sites use 2048bit encryption.

 

One solution is SSL inspection and selective decryption which is offered on the iboss SWG. Inspection looks at the SSL/TLS certs to determine if the base domain should be allowed or not. You can then fully decrypt the traffic based on a selective list – for example just decrypt Google and YouTube. We have seen that the proxy on a single iboss appliance can handle decryption of over 1500 simultaneous users without any significant speed impact, and of course all other traffic uses the Layer 2 bridge so still runs at wire speed.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...