Note
On Network Security appliances, the maximum transmission unit (MTU) for the management interfaces are set to 1500 bytes by default. Data ports are set to 1600 bytes by default. Before you enable SSL interception on a port pair, make sure that the MTU of the port pair is synchronized with the next-hop MTU. Use the "
interface <port-pair-name> mtu <bytes>" command to change if required.
Follow these best practices for SSL interception deployment:
Test the SSL interception feature in a lab environment first. Begin with a small number of users in the first phase. Identify any applications that do not function when SSL interception is enabled, such as applications that are highly sensitive to higher latency (for example, audio or video applications). Trellix recommends that you whitelist the domains so that SSL interception is bypassed for these applications.
Some desktop applications and smartphone mobile apps pin the public key to websites that they are connected to. When SSL interception is enabled on the Network Security appliance, you must whitelist the domains for applications that use the pinned public key.
Some websites require mutual authentication between the client and server. When SSL interception is enabled on the appliance, you must whitelist the domains for the relevant websites.