The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Actions for SSL Decryption Exclusions

Prev Next

To add SSL decryption exclusions in the Manager, complete these tasks:

  1. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → SSL Decryption Exclusions.

  2. Add an SSL decryption exclusion.

    1. In the SSL Decryption Exclusions page, click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png.

      The Rule Details panel appears.

      Rule Details panel for SSL Decryption Exclusion
      Rule Details panel for SSL Decryption Exclusion


      Option

      Definition

      State

      State of the exclusion. The state can either be Enabled or Disabled.

      Name

      Name for the exclusion.

      Comment

      Additional comments for the exclusion.

      Updated

      Displays the user who last modified the exclusion.

      Owner Domain

      Displays the name of the admin domain under which the outbound SSL decryption exclusion is added.

      Editable here

      Displays Yes if the exclusion is owned by the current admin domain. Displays No if the exclusion is not owned by the current admin domain.

      Scope

      Device

      Device or interface to which you want to assign the exclusion.

      The actions supported are add and delete.

      Note

      If the Scope is not specified for the exclusion, the exclusion will be applied to all the Sensors connected to the Manager that has SSL Decryption enabled.

      Source Endpoint

      New

      Source endpoint IP address or CIDR to which you want to assign the exclusion.

      The actions supported are add, create, edit, and delete.

      Click Add to add a rule object.

      Note

      The Manager filters the rule objects containing more than 10 entries and lists only those which contain up to 10 entries, since the maximum supported rule object members per rule object in SSL Decryption Exclusions is 10.

      Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png to create a new rule object.

      Click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png to edit or view a rule object.

      Click GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png to remove the rule object from the list.

      Destination Endpoint

      New

      Destination endpoint IP address or CIDR to which you want to assign the exclusion.

      The actions supported are add, create, edit, and delete.

      Click Add to add a rule object.

      Note

      The Manager filters the rule objects containing more than 10 entries and lists only those which contain up to 10 entries, since the maximum supported rule object members per rule object in SSL Decryption Exclusions is 10.

      Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png to create a new rule object.

      Click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png to edit or view a rule object.

      Click GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png to remove the rule object from the list.

      Destination URL Hostname

      URL hostname of the destination to which the outbound SSL decryption exclusion is assigned to.

      The actions supported are add, create, edit, and delete.

      Click Add to add a rule object.

      Note

      The Manager filters the rule objects containing more than 10 entries and lists only those which contain up to 10 entries, since the maximum supported rule object members per rule object in SSL Decryption Exclusions is 10.

      Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png to create a new rule object.

      Click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png to edit or view a rule object.

      Click GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png to remove the rule object from the list.

      Note

      The Sensor uses SSL extension "Server Name Indication" (SNI) in the "CLIENT HELLO" message to get the host name and category. If SNI is absent, the Sensor cannot match against these exclusions.

      Destination URL Category

      URL category for which you want to assign the exclusion. The Manager retrieves the list of URL categories from the GTI server. It can retrieve the list from the Public GTI cloud or the Private GTI cloud based on the configuration.

      Note

      If Alert Data Details is not enabled in the Manager → <Admin Domain Name> → Integration → GTI page, URL category is disabled. Also, DNS resolution must be enabled in the Sensor for functioning of GTI.

      The actions supported are add and delete.

    2. Click Save.

      The SSL decryption exclusion is displayed in the SSL Decryption Exclusions pane.

  3. Select the exclusion and click GUID-717A81EC-A913-4C2F-B61C-0129ED30387A-low.png to clone an SSL decryption exclusion.

    Note

    You can use the Search function to find the SSL decryption exclusion.

  4. Double-click the row of the exclusion to modify. The Rule Details panel is displayed. You can edit the values for the fields.

  5. Select the exclusion, click GUID-9A719AD5-F6BE-4CD4-9311-CC6655DF9B70-low.png to delete the exclusion.

  6. Click Save as CSV to export the SSL decryption exclusions list as a .csv file.