SV3800, SV3800B, and SV3800B-20 Security Policy
2016 Symantec Corporation This document may be freely reproduced & distributed whole & intact including this copyright
notice.
12
Figure 2
–3
Passive-Tap Configuration
By allowing the attached security appliance to view a decrypted version of SSL/
TLS traffic, the SSL Visibility Appliance enables the security appliance to detect/
block threats that are hidden within encrypted SSL/TLS flows. As the percentage
of SSL/TLS traffic in networks is growing significantly with increasing use of Web
2.1
applications and Cloud based applications, it is increasingly important that
network security appliances can do their job even when the traffic is sent over
SSL/TLS connections.
Detecting, intercepting, decrypting and re-encrypting SSL/TLS traffic is a
complex and computationally intense activity. Providing SSL/TLS inspection
capabilities in a device that can be placed in-line in either a Gigabit Ethernet or 10
Gigabit Ethernet network link and which will not cause a performance bottleneck
requires hardware acceleration. In the case of the SV3800/SV3800B/SV3800B-20,
this acceleration is provided by a Netronome Network Flow Engine (NFE) card
that contains two of Netronome’s NFP-3240 flow processor chips. Each NFP-
3240 contains 40 cores optimized for processing network traffic and provides
significant acceleration and offload for the standard CPUs used on the
SV3800/SV3800B/SV3800B-20 motherboards.