The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Adding or deleting SSL decryption mirroring

Prev Next

You can add or delete mirroring of SSL decrypted traffic on one or more monitoring interface pairs by using the Network Security appliance Web UI or CLI:

When you add mirroring of SSL decrypted traffic on at least one monitoring interface pair that is configured for inline deployment, the Network Security appliance will mirror SSL decrypted traffic over a mirror port in tap mode. The destination TCP port can be changed in the SSL decrypted packet before the packet is mirrored. This can be useful when you want to send SSL decrypted traffic back to a security device for analysis. The SSL decrypted traffic serves as a distinct session on the security device. If a virtual local area network (VLAN) identification number is not present in the original HTTPS traffic, the VLAN identification number is configured so that the VLAN ID is inserted into the decrypted mirrored packet.

When you delete mirroring of SSL decrypted traffic on a monitoring interface pair, the appliance will not mirror or track SSL decrypted traffic to an external device.

By default, SSL decryption mirroring is disabled.

Note

If the mirror port is configured in tap mode, the mirroring of SSL decrypted traffic cannot be enabled.

If you want the appliance to mirror or track SSL decrypted traffic to an external device, you must enable SSL interception on a network port pair. For details about how to enable SSL interception, see Enabling or disabling SSL interception.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A minimum of two interface pairs on the Network Security appliance

  • Verify that the monitoring interface pair is configured in inline mode (monitor or block mode) for SSL decryption mirroring by using the show policymgr interfaces command. For details about how to configure inline operational modes, see Configuring inline operational modes.

  • Specify the monitoring interface pair and the mirror port. Use the policymgr interface <interfacePair> mirror port <portName> command. Verify that the interface pair that serves as the mirror port is in tap mode. Use the show policymgr interfaces command.

    For details about how to configure a mirror port on an interface, see Configuring the Network Security appliance to forward traffic from a mirror port using the CLI.