Name

HTTH-936 — Skipping SNI inspection in empty message

Severity

N (notify)

Message text

Skipping SNI inspection in unknown protocol, empty message

Description

The request looks like a correct SSLv3/TLS handshake message except it is empty, even handshake type is missing. Unknown protocol is therefore assumed so SNI inspection is skipped and server IP address is used in ACL matching instead of hostname from the SNI inspection. URI is also left unchanged.

See also

logging(7)

Authors

This man page is a part of Kernun Firewall.
Copyright © 2000–2023 Trusted Network Solutions, a. s.
All rights reserved.