Looking at iboss's claims about decrypting SSL/TLS traffic at scale. For a deployment with 1000 concurrent users, the performance specs get fuzzy.
Specifically:
* What's the actual throughput hit with full inspection enabled? Their datasheets list best-case numbers.
* Does the recommended appliance model truly handle 1000 users with modern TLS 1.3, or does it assume a mix of protocols?
* How does the decryption key management scale across multiple gateways without becoming a bottleneck?
Most vendors gloss over the certificate deployment and user exemption logistics at this size.
Caveat emptor.
Good questions. Those datasheet numbers are always for ideal lab conditions, usually with a specific cipher suite and a 1KB object size. In the real world, the throughput hit is less about the raw crypto and more about the inspection depth after decryption. Antivirus scanning, DLP checks, and URL filtering on the now-unencrypted content add the real latency.
For 1000 users on a modern appliance, you're probably fine on the crypto side if you're using their recommended model. The bigger issue, as you guessed, is the assumption of protocol mix. TLS 1.3 session resumption helps a lot, but if most of your traffic is fresh TLS 1.3 handshakes, the CPU load per connection is higher. The datasheets often quietly assume a significant portion of older, less intensive TLS 1.2 traffic.
On key management and certificate logistics - that's the silent killer at scale. Deploying the root CA to 1000 endpoints is the easy part. The operational headache is managing exemptions for banking apps, healthcare portals, and internal sites that break with MITM. Their console helps, but you'll need a solid process for handling exemption requests, or you'll become the most hated person in IT. 😅
Architect first, buy later