You can add or delete mirroring of SSL decrypted traffic on one or more monitoring interface pairs by using the Network Security appliance Web UI or CLI:
When you add mirroring of SSL decrypted traffic on at least one monitoring interface pair that is configured for inline deployment, the Network Security appliance will mirror SSL decrypted traffic over a mirror port in tap mode. The destination TCP port can be changed in the SSL decrypted packet before the packet is mirrored. This can be useful when you want to send SSL decrypted traffic back to a security device for analysis. The SSL decrypted traffic serves as a distinct session on the security device. If a virtual local area network (VLAN) identification number is not present in the original HTTPS traffic, the VLAN identification number is configured so that the VLAN ID is inserted into the decrypted mirrored packet.
When you delete mirroring of SSL decrypted traffic on a monitoring interface pair, the appliance will not mirror or track SSL decrypted traffic to an external device.
By default, SSL decryption mirroring is disabled.
Note
If the mirror port is configured in tap mode, the mirroring of SSL decrypted traffic cannot be enabled.
If you want the appliance to mirror or track SSL decrypted traffic to an external device, you must enable SSL interception on a network port pair. For details about how to enable SSL interception, see Enabling or disabling SSL interception.
Prerequisites
Administrator or Operator access to the Network Security appliance
A minimum of two interface pairs on the Network Security appliance
Verify that the monitoring interface pair is configured in inline mode (monitor or block mode) for SSL decryption mirroring by using the
show policymgr interfacescommand. For details about how to configure inline operational modes, see Configuring inline operational modes.Specify the monitoring interface pair and the mirror port. Use the
policymgr interface <interfacePair> mirror port <portName>command. Verify that the interface pair that serves as the mirror port is in tap mode. Use theshow policymgr interfacescommand.For details about how to configure a mirror port on an interface, see Configuring the Network Security appliance to forward traffic from a mirror port using the CLI.