The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring advanced SSL settings for SSL interception using the CLI

Prev Next

Use the commands in this section to configure the advanced SSL settings for SSL interception. You also can specify an unlimited number of TCP ports on the network port pair that is configured on the appliance interface. For details about how to configure TCP ports for SSL interception, see Adding or deleting a TCP port for SSL interception using the CLI .

Note

Use the show crypto cipher-list custom ssl command to view the list of inbound SSL ciphers and outbound SSL ciphers.

Use the crypto cipher-list custom ssl-cipher-list command to create a custom cipher list.

To configure the advanced SSL settings:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Set the port pair op-mode to desired mode (block or monitor).

    (config) # policymgr interface A op-mode monitor
  3. Set server TCP ports.

    (config) # policymgr ssl-intercept config tcp port 443
  4. Apply changes by enabling SSL-intercept on desired port pair.

    (config) # policymgr interface A ssl-intercept enable
  5. Specify the minimum TLS version required for inbound SSL interception connections.

    hostname (config) # policymgr ssl-intercept config inbound min-version{tls1 | tls1.1 | tls1.2}

    The default value is TLS v1.2.

  6. Specify the cipher list for inbound SSL interception and TLS connections.

    hostname (config) # policymgr ssl-intercept config inbound cipher-list{original | fips | fips-high-security | cc-ndpp | cc-ndpp-highsecurity | fips-and-cc-ndpp | fips-and-cc-ndpp-high-security | compatible | custom}
  7. Specify the minimum TLS version required for outbound SSL interception connections.

    hostname (config) # policymgr ssl-intercept config outbound min-version policymgr ssl-intercept config outbound min-version {tls1 | tls1.1 | tls1.2}

    The default value is TLS v1.2.

  8. Specify the cipher list for outbound SSL interception and TLS connections.

    hostname (config) # policymgr ssl-intercept config outbound cipher-list {original | fips | fips-high-security | cc-ndpp | cc-ndpp-highsecurity | fips-and-cc-ndpp | fips-and-cc-ndpp-high-security | compatible | custom}
  9. Specify the SSL interception certificate that is issued by a trusted public certificate authority (CA) or your own organization.

    hostname (config) # policymgr ssl-intercept config certificate trusted <certificateName>

    where <certificateName> is the name of your choice for the SSL interception certificate.

  10. Specify the SSL interception certificate that acts as an untrusted certificate.

    hostname (config) # policymgr ssl-intercept config certificate untrusted <certificateName>

    where <certificateName> is the name of your choice for the SSL interception certificate that is not trusted by the system.

  11. Save your changes.

    hostname (config) # write memory

To configure Inbound SSL settings:

  1. Go to CLI configuration mode.

    hostname > enable
    
    hostname # configure terminal
  2. Set the port pair op-mode to desired mode (block or monitor).

    (config) # policymgr interface A op-mode block
  3. Import Server certificate(s) and private key(s) using existing CLI.

    (config) # crypto certificate name my_server public-cert pem "-----BEGIN ...
    (config) # crypto certificate name my_server private-key pem "-----BEGIN ...
  4. Add imported certificate(s) to SSL-intercept server certificates list.

    (config) # policymgr ssl-intercept config certificate server my_server
  5. Set server TCP ports.

    (config) # policymgr ssl-intercept config tcp port 443
  6. Switch to server protection mode.

    (config) # policymgr ssl-intercept config reverse-proxy enable
  7. Apply changes by enabling SSL-intercept on desired port pair.

    (config) # policymgr interface A ssl-intercept enable