Use the commands in this section to add a rule to a network policy based on the IPv4 or IPv6 address and mask length or to delete a rule from a network policy using the CLI.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Specify the IPv4 or IPv6 address and mask length in CIDR format for the network policy rule.
hostname (config) # policymgr ssl-intercept network ip <IP_address> <mask>
where:
<IP_address>is the destination IPv4 or IPv6 address or source IPv4 or IPv6 address. To match any IP address for the network port pair, enter any. Only IP addresses are supported.<mask>is the IPv4 or IPv6 mask length in CIDR format prefixed by a slash (for example, /24). To match any mask length, enter any.
Specify the network port pair for the policy rule.
hostname (config) # policymgr ssl-intercept network ip <IP_address> <mask_length> interface <port-pair-name>
where:
<port-pair-name>is the designation (A through F) that is configured on the appliance interface for inline deployment. To specify all the network port pairs, enter ALL.
Specify the match condition.
hostname (config) # policymgr ssl-intercept network ip <IP_address> <mask_length> interface <port-pair-name> {decrypt | pass-through} {match-destination | match-source}Enter match-destination to match the ip with destination ip.
Enter match-source to match the ip with source ip.
No value to match the ip with either
Specify the type of action for the network policy rule.
hostname (config) # policymgr ssl-intercept network ip <IP_address> <mask_length> interface <port-pair-name> {decrypt | pass-through}Enter decrypt to decrypt HTTPS traffic that matches the rule. This is the default action for the network policy rule.
Enter pass-through to bypass traffic that matches the rule.
Repeat the preceding steps to add additional rules.
Verify the status of the network policy rules configuration for SSL interception.
hostname (config) # show policymgr ssl-intercept network Total CIDR Rule Supported: 512 Total CIDR Rule Configured: 2 INTF IP VLAN ACTION ALL 2002:470:84a7:1720:ae1f:6bff:fe12:3e03/128 ALL decrypt match-source ALL 4.4.4.2/32 11.14.32.0/24 ALL decrypt match-destination
The "Total CIDR Rule Configured" line displays the total number of rules that you added to a network policy.
Save your changes.
hostname (config) # write memory
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Delete the network policy rule.
hostname (config) # no policymgr ssl-intercept network ip <IP_address> <mask_length> interface <port-pair-name>
Where:
<IP_address>is the destination IPv4 or IPv6 address or source IPv4 or IPv6 address. To match any IP address for the network port pair, enter any.<mask>is the IPv4 or IPv6 mask length in CIDR format prefixed by a slash (for example, /24). To match any mask length, enter any.<port-pair-name>is the designation (A through F) that is configured on the appliance interface for inline deployment. To specify all the network port pairs, enter ALL.
Repeat the preceding steps to delete additional rules.
Verify the status of the network policy rules configuration for SSL interception.
hostname (config) # show policymgr ssl-intercept network Total CIDR Rule Supported: 512 Total CIDR Rule Configured: 1 INTF IP VLAN ACTION ALL 2002:470:84a7:1720:ae1f:6bff:fe12:3e03/128 ALL decrypt match-source
The "Total CIDR Rule Configured" line displays the total number of rules that remain in a network policy.
Save your changes.
hostname (config) # write memory