Use the commands in this section to add mirroring of SSL decrypted traffic or to delete mirroring of SSL decrypted traffic from the monitoring interface pair on the Network Security appliance.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Enable mirroring of SSL decrypted traffic on the monitoring interface pair.
hostname (config) # policymgr interface <interfacePair> ssl-intercept mirror enable
where
<interfacePair>is the interface pair that is already configured in inline mode (monitor or block mode) for SSL decryption mirroring and the mirror port is in tap mode.(Optional) Specify a new destination TCP port number to modify the SSL decrypted packet before it is mirrored.
hostname (config) # policymgr interface <interfacePair> ssl-intercept mirror tcp-port <portNumber>
where
<portNumber>is the destination TCP port number.(Optional) Specify the VLAN identification number so that the tag is inserted into the decrypted mirrored packet.
hostname (config) # policymgr interface <interfacePair> ssl-intercept mirror vlan <vlanID>
where
<vlanID>is the VLAN identification number. The range is from 1 to 4094.Save your changes.
hostname (config) # write memory
Verify the status of mirroring SSL decrypted traffic.
hostname (config) # show policymgr interfaces Policy enabled: yes Interface A Active : yes op mode : block (enforcing) fail-safe : close policy : mixed tolerance : 1 Ports : pether3 pether4 QinQ : no QinQ-evet : 0x88a8 Mirror: Non-SSL : no SSL : yes TCP Port : 456 vlan : 545 Port : pether9 ........
The "Mirror SSL" line displays "yes" if mirroring is added for SSL decrypted traffic.
To delete mirroring of SSL decrypted traffic from an interface:
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Delete mirroring of SSL decrypted traffic from an interface pair.
hostname (config) # no policymgr interface <interfacePair> sslintercept mirror enable
where
<interfacePair>is the monitoring interface pair.If a new destination TCP port number has already been specified, delete the destination TCP port number from an interface pair.
hostname (config) no policymgr interface <interfacePair> sslintercept mirror tcp-port <portNumber>
where
<portNumber>is the destination TCP port number.If the VLAN identification number has already been specified, delete the VLAN ID from an interface pair.
hostname (config) # no policymgr interface <interfacePair> sslintercept mirror vlan <vlanID>
Delete the mirror port from an interface.
hostname (config) # policymgr interface <interfacePair> mirror clear
where
<interfacePair>is the monitoring interface pair that is forwarding traffic.Save your changes.
hostname (config) # write memory
Verify the status of mirroring SSL decrypted traffic.
hostname (config) # show policymgr interfaces
Policy enabled: yes Interface A Active : yes op mode : block (enforcing) fail-safe : close policy : mixed tolerance : 1 Ports : pether3 pether4 QinQ : no QinQ-evet : 0x88a8 Mirror: Non-SSL : no SSL : no Port : ........
The "Mirror SSL" line displays "no" if mirroring is deleted for SSL decrypted traffic.