This is bad? Why can't my xgs decrypt all traffic?


This thread was automatically locked due to age.
This is bad? Why can't my xgs decrypt all traffic?


Look at your Firewall and TLS rules, along with the TLS exceptions group. There are fairly large swaths of sites (Apple, Microsoft, etc) that are in the exceptions group because it will break the site. You may also have placed exceptions in the local exceptions group -- like banking sites, etc. I, too, was shocked by the numbers at first, but at least in your case you have about 40% of your traffic that were more fully vetted because of the TLS decryption that did take place.