Solved
Netskope client SSL decryption issues
Our Real-time protection policies are simple - block high risk websites, allow enterprise websites and alert uploads and downloads of social media. No NPA. We have multiple issues with traffic passing through Netskope SSL decryption.
Few issues we noticied so far (be it any browser - firefox, chrome, edge or tor)
- websites (with SSL decryption) are intermittently not loaded (one day they work fine, next day they won't and the cycle repeats again)
- websites (with SSL decryption) are extremely slow
- downloading objects like 200MB files takes high times (minutes to hours)
- few websites have their dynamic buttons disabled or not becoming live
- there are instances the websites failed won't show in debug logs, application & page events & alerts. Clearly killed by Netskope client, but not logged or sent to cloud. The websites works as soon as we mention in SSL BYPASS.
Same sites with SSL bypass
- websites (with SSL bypass) are loading every time without intermittent issues
- websites (with SSL bypass)) are loading faster every time
- downloading objects like 200MB files takes few seconds
- websites having their dynamic buttons work as expected.
So, our current workaround is, if any Netskope client complains about a website, we are adding them to SSL bypass. However, it beats the purpose of inspection because traffic left encrypted will not be further analyzed by Netskope. Important inspection and detection capabilities will not be useful. We have Netskope cases logged, but clear cause hasn't been found yet.
We believe Netskope client and cloud are rewriting headers and content which causes overload and minor delays are understandable. However, the performance dropping by 10 times is not ideal. Admin guide and KBs don't mention or talk about the throughput times or performance improving features, unlike onsite appliances where a company can pick high specification models for faster throughputs and higher performance.
We are reaching out to community to see if others noticed these issues & how they overcome issues instead of SSL Bypass. Please share your ideas.
Best answer by Indu
Thanks ark007 for your suggestions. We are already following setup as per KB. Using Digital Experience Management, we noticed that client to Netskope POP latency is ok, but Netskope POP to app latency is high. We are dealing this with Netskope support.
Reply
Login to the community
If you haven't already registered, now is a good time to do so. After you register, you can post to the community, receive email notifications, and lots more. It's quick and it's free! Create an account
Login with SSO
Employee Partneror
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.