To add a proxy rule, perform the following steps:
Select Devices → <Admin Domain Name> → Global → IPS Device Settings → SSL Decryption.
In the Inbound tab, select Inbound Proxy Rules tab.
Click
to add a rule above the selected rule.Click
to add a rule below the selected rule.The rule details pane opens.
Enter the name of the rule.
Enter the IPv4 or IPv6 CIDR of the web server you wish to protect.
Enter the comment for the rule.
Select the web server certificate from the drop down in the Web Server Certificates pane.
Click Add.
(Optional) Click Set as default to set the selected web server certificate as default certificate.
The Installed On pane displays the Sensor on which the web server certificate is saved on.
Important
From 11.1 Update 8 release, once Inbound Proxy is enabled, all Inbound traffic will be decrypted; a proxy rule with a specific web server IP is not required for proxy decryption.
Note
If you do not specifically set a default, the first certificate in the list is set as the default certificate.
Note
If the server supports Server Name Indication (SNI), multiple certificates must be available in the Sensor.
Click Save to save the rule order details.