You can configure the advanced SSL settings for SSL interception by using the Network Security appliance Web UI or CLI:
You must configure inbound and outbound SSL interception connections that are part of the advanced SSL settings. A cipher list must be associated with each SSL connection. Inbound connections are HTTPS connections that start from an external network and connect to the network. The Network Security appliance can match the server name identification (SNI) sent by the client or server name from the server certificate against the database to determine whether the client TCP connection is decrypted or bypassed. The Network Security appliance uses the original server certificate and private key to initiate the SSL connection with the client. A new SSL connection is established with the server. Outbound connections are HTTPS connections that start from an internal client and connect to the Internet. If a rule does not match the contents of the database, the packet is not decrypted.
Note
A stronger TLS version and ciphers can be used for the client-facing port. A weaker TLS version and ciphers can be used for the server-facing port.
You can add a TCP port on the network port pair that is configured on the appliance interface. By default, port 443 is used as the TCP listener to check for incoming connection requests. The TCP listener receives secure HTTPS connections between the client and the back-end server on one or more port pairs.
Prerequisites
Administrator or Operator access to the Network Security appliance
Verify that you have configured the appliance for inline deployment with a network port pair by using the
show policymgr interfacescommand. For details about how to configure inline operational modes, see Configuring inline operational modes.You have imported the public and private keys for a trusted SSL interception CA certificate and an untrusted SSL interception CA certificate. For details about how to import the SSL CA certificate, see Importing an SSL CA certificate using the Web UI or Importing an SSL interception CA certificate using the CLI.
You have exported the public key issuer certificate that is trusted by a trusted public CA or that acts as an untrusted certificate. For details about how to export the public key for an SSL CA certificate, see Exporting an SSL CA certificate using the Web UI.