You can add or delete port mirroring for all traffic types (including SSL encrypted traffic) on the Network Securitymonitoring interface pair by using the Network Security appliance Web UI or CLI:
When you add port mirroring for all traffic types (including SSL traffic) on at least one monitoring interface pair, the Network Security appliance will forward a copy of the network traffic that it processed to another port on the same appliance that is configured in tap mode. The SSL traffic remains encrypted when it is forwarded to another analysis device. When you delete port mirroring for all traffic types on a monitoring interface pair, the Network Security appliance will not forward a copy of the traffic to a mirror port.
Prerequisites
Administrator or Operator access to the Network Security appliance
A minimum of two interface pairs on the Network Security appliance
Specify the monitoring interface pair and the mirror port. Use the
policymgr interface <interfacePair> mirror port <portName>command. Verify that the interface pair that serves as the mirror port is in tap mode. Use theshow policymgr interfacescommand.For details about how to configure a mirror port on an interface, see Configuring the Network Security appliance to forward traffic from a mirror port using the CLI.