The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

About SSL interception (HTTPS and HTTPS/2)

Prev Next

SSL/TLS protocols provide a secure communication between clients and servers. SSL/TLS traffic (also referred to as HTTPS) can pose a security risk that can hide malicious traffic and user activity. SSL interception is a feature that provides visibility into HTTPS traffic for malware detection. SSL interception enables a appliance, deployed between a Web client and Web server, to act as a proxy to intercept and decrypt HTTPS traffic and inspect the traffic for indicators of malicious activity.

SSL interception is disabled by default. After you enable SSL interception for specific network port pairs, the Network Security appliance analyzes the encrypted parts of HTTPS traffic passed between the port pairs. If you have configured the appliance to generate alerts from HTTPS traffic based on SSL interception, you can view the analysis results on the Alerts > Alerts > Alerts page in the Web UI. The HTTPS/2 alerts can be detected by enabling ALPN configuration. For more information on how to enable ALPN configuration see, Enabling or disabling ALPN configuration using CLI.

The Network Security appliance can pass the authentication credentials from the client to the server. The Network Security appliance uses certificates to establish a trusted third-party (man in the middle, or MitM) connection between the client and server. The Network Security appliance presents a fake server certificate to the client and establishes an SSL connection.

The Network Security appliance also acts as a client to the actual server and establishes another connection. The actual client can now assume that the connection is with the real server. A trusted enterprise root certificate already has been installed in the client browser. Because the fake certificate is signed by a secondary intermediate certificate that is signed by the enterprise root certificate, the client accepts the fake server certificates as trusted. Each TCP SSL connection from the client creates two distinct TCP SSL connections on the Network Security appliance—one client connection and one server connection.

Supported appliances

SSL interception is supported on the following Classic product edition appliances and virtual appliances:

  • NX 2500, NX 2550, NX 3500, NX 4500, NX 5500, NX 6500, NX 8600, and NX 10550

  • NX 2500V, NX 2501V, NX 2550V, NX 4500V, and NX 6500V

SSL interception is not supported on SmartVision Mode appliances.

Cipher mirroring

Ciphers and TLS versions advertised by client are mirrored to the TLS connection with the server. Ciphers and TLS versions selected by server are mirrored to the TLS connections with the client.

Cipher mirroring is not supported on virtual appliances.

Optional CIDR policy rules

You can configure the rules for a network policy on the Network Security appliance to control which traffic to decrypt or whitelist based on the destination IPv4 address, source IPv4 address, or mask in CIDR format. You can configure rules for a specified network port pair or all network port pairs. IPv6 addresses are not supported.

You can configure SSL interception on the Network Security appliance using a policy that controls which traffic to bypass based on URL categories and category groups. You can use them to control access to URLs by type. For example, you can bypass all URLs considered as “professional networking.” A predefined Trellix exclusion list is also used to exclude the domains from decryption. The feature is disabled by default and must be configured and enabled.

Optional whitelist categories

You may want to configure an SSL interception whitelist option.

  • A service needs end-to-end communication and the service does not support Server Name Indication (SNI) in the SSL handshake. This feature is disabled by default and must be enabled.

  • Categorized third-party URLS. This feature is disabled by default and must be enabled. The url-category lookup enable command must be enabled.

  • Disable the SSL interception URL category whitelist feature. This feature is enabled by default.