Enable both OCSP and CRL certificate checking.
If you Block sessions on certificate status check
timeout in the Forward Proxy Decryption profile and
are concerned that 5 seconds is not enough time and may result in
too many sessions blocked by timeouts, set the Receive
Timeout (sec) to a longer amount of time.