Use the commands in this section to configure the advanced SSL settings for SSL interception. You also can specify an unlimited number of TCP ports on the network port pair that is configured on the appliance interface. For details about how to configure TCP ports for SSL interception, see Adding or deleting a TCP port for SSL interception using the CLI .
Note
Use the
show crypto cipher-list custom sslcommand to view the list of inbound SSL ciphers and outbound SSL ciphers.Use the
crypto cipher-list custom ssl-cipher-listcommand to create a custom cipher list.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Set the port pair op-mode to desired mode (block or monitor).
(config) # policymgr interface A op-mode monitor
Set server TCP ports.
(config) # policymgr ssl-intercept config tcp port 443
Apply changes by enabling SSL-intercept on desired port pair.
(config) # policymgr interface A ssl-intercept enable
Specify the minimum TLS version required for inbound SSL interception connections.
hostname (config) # policymgr ssl-intercept config inbound min-version{tls1 | tls1.1 | tls1.2}The default value is TLS v1.2.
Specify the cipher list for inbound SSL interception and TLS connections.
hostname (config) # policymgr ssl-intercept config inbound cipher-list{original | fips | fips-high-security | cc-ndpp | cc-ndpp-highsecurity | fips-and-cc-ndpp | fips-and-cc-ndpp-high-security | compatible | custom}Specify the minimum TLS version required for outbound SSL interception connections.
hostname (config) # policymgr ssl-intercept config outbound min-version policymgr ssl-intercept config outbound min-version {tls1 | tls1.1 | tls1.2}The default value is TLS v1.2.
Specify the cipher list for outbound SSL interception and TLS connections.
hostname (config) # policymgr ssl-intercept config outbound cipher-list {original | fips | fips-high-security | cc-ndpp | cc-ndpp-highsecurity | fips-and-cc-ndpp | fips-and-cc-ndpp-high-security | compatible | custom}Specify the SSL interception certificate that is issued by a trusted public certificate authority (CA) or your own organization.
hostname (config) # policymgr ssl-intercept config certificate trusted <certificateName>
where
<certificateName>is the name of your choice for the SSL interception certificate.Specify the SSL interception certificate that acts as an untrusted certificate.
hostname (config) # policymgr ssl-intercept config certificate untrusted <certificateName>
where
<certificateName>is the name of your choice for the SSL interception certificate that is not trusted by the system.Save your changes.
hostname (config) # write memory
To configure Inbound SSL settings:
Go to CLI configuration mode.
hostname > enable
hostname # configure terminal
Set the port pair op-mode to desired mode (block or monitor).
(config) # policymgr interface A op-mode block
Import Server certificate(s) and private key(s) using existing CLI.
(config) # crypto certificate name my_server public-cert pem "-----BEGIN ...
(config) # crypto certificate name my_server private-key pem "-----BEGIN ...
Add imported certificate(s) to SSL-intercept server certificates list.
(config) # policymgr ssl-intercept config certificate server my_server
Set server TCP ports.
(config) # policymgr ssl-intercept config tcp port 443
Switch to server protection mode.
(config) # policymgr ssl-intercept config reverse-proxy enable
Apply changes by enabling SSL-intercept on desired port pair.
(config) # policymgr interface A ssl-intercept enable