Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL/TLS inspection - Dropped due to TLS engine error: OUT_OF_MEMORY[201]

Hello,

I have problems with a few clients to access some pages. In the browser appears a SSL_PROTOCOL_ERROR. In the log viewer in the module SSL/TLS inspection appears the error "Dropped due to TLS engine error: OUT_OF_MEMORY[201". For some the error occurs only via VPN, for some directly from the LAN. What exactly does this error mean?

Here is an example from the log:

messageid="19006" log_type="Content Filtering" log_component="SSL" log_subtype="Error" severity="Information" user="xxx" src_ip="x.x.x.x" dst_ip="40.126.31.70" user_group="VPN-User" src_country="R1" dst_country="IRL" src_port="49893" dst_port="443" app_name="" category="Information Technology" con_id="894151296" rule_id="2" profile_id="4" rule_name="Decrypt" profile_name="Decrypt" bitmask="Valid" key_type="KEY_TYPE__RSA" key_param="RSA 2048 bits" fingerprint="" resumed="1" cert_chain_served="TRUE" cipher_suite="TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384" sni="login.live.com" tls_version="TLS1.2" reason="Dropped due to TLS engine error: OUT_OF_MEMORY[201]" exception="" message=""

Thanks.



This thread was automatically locked due to age.
Parents
  • Hi,

    I had the exact same issue with SSL/TLS decryption via IPSec Remote Access Tunnel. Support told me to change the MTU of the ipsec0 interface via the following command. 

    ifconfig ipsec0 mtu 1500

    !!! (All IPSec tunnels are going to restart after making the change) !!!

    After changing the MTU SSL/TLS decryption was working fine again.

    I was pretty confused that the MTU was set to 16240 for ipsec0 interface before I have made the changes.

Reply
  • Hi,

    I had the exact same issue with SSL/TLS decryption via IPSec Remote Access Tunnel. Support told me to change the MTU of the ipsec0 interface via the following command. 

    ifconfig ipsec0 mtu 1500

    !!! (All IPSec tunnels are going to restart after making the change) !!!

    After changing the MTU SSL/TLS decryption was working fine again.

    I was pretty confused that the MTU was set to 16240 for ipsec0 interface before I have made the changes.

Children