The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Adding or deleting SSL decryption mirroring using the CLI

Prev Next

Use the commands in this section to add mirroring of SSL decrypted traffic or to delete mirroring of SSL decrypted traffic from the monitoring interface pair on the Network Security appliance.

To add mirroring of SSL decrypted traffic on an interface:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enable mirroring of SSL decrypted traffic on the monitoring interface pair.

    hostname (config) # policymgr interface <interfacePair> ssl-intercept mirror enable

    where <interfacePair> is the interface pair that is already configured in inline mode (monitor or block mode) for SSL decryption mirroring and the mirror port is in tap mode.

  3. (Optional) Specify a new destination TCP port number to modify the SSL decrypted packet before it is mirrored.

    hostname (config) # policymgr interface <interfacePair> ssl-intercept mirror tcp-port <portNumber> 

    where <portNumber> is the destination TCP port number.

  4. (Optional) Specify the VLAN identification number so that the tag is inserted into the decrypted mirrored packet.

    hostname (config) # policymgr interface <interfacePair> ssl-intercept mirror vlan <vlanID>

    where <vlanID> is the VLAN identification number. The range is from 1 to 4094.

  5. Save your changes.

    hostname (config) # write memory
  6. Verify the status of mirroring SSL decrypted traffic.

    hostname (config) # show policymgr interfaces
    
    Policy enabled: yes
    
    Interface A
      Active      : yes
      op mode     : block (enforcing)
      fail-safe   : close
      policy      : mixed
      tolerance   : 1
      Ports       : pether3  pether4
      QinQ        : no
      QinQ-evet   : 0x88a8
      Mirror:
        Non-SSL   : no
       SSL       : yes TCP Port : 456  vlan : 545
       Port      : pether9
    ........

    The "Mirror SSL" line displays "yes" if mirroring is added for SSL decrypted traffic.

To delete mirroring of SSL decrypted traffic from an interface:

  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Delete mirroring of SSL decrypted traffic from an interface pair.

    hostname (config) # no policymgr interface <interfacePair> sslintercept
    mirror enable

    where <interfacePair> is the monitoring interface pair.

  3. If a new destination TCP port number has already been specified, delete the destination TCP port number from an interface pair.

    hostname (config) no policymgr interface <interfacePair> sslintercept
    mirror tcp-port <portNumber>

    where <portNumber> is the destination TCP port number.

  4. If the VLAN identification number has already been specified, delete the VLAN ID from an interface pair.

    hostname (config) # no policymgr interface <interfacePair> sslintercept
    mirror vlan <vlanID>
    
  5. Delete the mirror port from an interface.

    hostname (config) # policymgr interface <interfacePair> mirror
    clear

    where <interfacePair> is the monitoring interface pair that is forwarding traffic.

  6. Save your changes.

    hostname (config) # write memory
  7. Verify the status of mirroring SSL decrypted traffic.

    hostname (config) # show policymgr interfaces
    
    Policy enabled: yes
    Interface A
    Active :    yes
    op mode :   block (enforcing)
    fail-safe : close
    policy :    mixed
    tolerance : 1
    Ports :     pether3 pether4
    QinQ :      no
    QinQ-evet : 0x88a8
    Mirror:
    Non-SSL : no
    SSL : no
    Port :
    ........

    The "Mirror SSL" line displays "no" if mirroring is deleted for SSL decrypted traffic.