The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring advanced SSL settings for SSL interception using the Web UI

Prev Next

Use the Advanced SSL Configuration area in the SSL Intercept Settings page to configure the advanced SSL settings for SSL interception using the Web UI.

NX_SSLIntercept_AdvancedSSL_scap.png

You specify the following advanced SSL settings for SSL interception.

Field

Description

Reverse Proxy

NX intercepts inbound HTTPS connections initiated by a client towards a server, while preserving the original server certificate. The original server certificate, along with its private key, should be imported into NX. The imported server's private key is used by NX to decrypt the incoming HTTPS traffic securely.

SSL Ports

TCP port to intercept HTTPS traffic on the port pair that is configured on the appliance interface. You can specify a maximum of 8 TCP ports for SSL interception.

Server Certificates

The imported original Sever certificate.

SSL Trusted Certificate

SSL certificate that is issued by a trusted public certificate authority (CA) or your own organization. For example, the SSL certificate that is trusted can have the name ssl-proxy-trusted.

SSL Untrusted Certificate

SSL certificate that acts as an untrusted certificate. For example, the SSL certificate that is not trusted can have the name ssl-proxy-untrusted.

Inbound TLS Minimum Version

Minimum TLS version required for inbound SSL interception connections. The default is TLS v1.2.

Inbound Cipher List

Cipher list associated with inbound SSL interception and TLS connections.

  • original—Original Trellix cipher list that is used for maximum compatibility.

  • fips—This cipher list is compliant with the Federal Information Processing Standard (FIPS) 140-2.

  • cc-ndpp—This cipher list is compliant with Common Criteria Network Device Protection Profile (CC-NDPP).

  • fips-and-cc-ndcpp—This cipher list is compliant with FIPS 140-2 and CC-NDPP.

  • high-security—High security option that might support ciphers that are not compliant with FIPS-140-2 and CC-NDPP.

  • compatible—Improved security that maintains backward compatibility.

  • custom—A user-created cipher list.

Outbound TLS Minimum Version

Minimum TLS version required for outbound SSL interception connections. The default is TLS v1.2.

Outbound Cipher List

Cipher list associated with outbound SSL interception and TLS connections.

  • fips—This cipher list is compliant with the Federal Information Processing Standard (FIPS) 140-2.

  • cc-ndpp—This cipher list is compliant with Common Criteria Network Device Protection Profile (CC-NDPP).

  • fips-and-cc-ndcpp—This cipher list is compliant with FIPS 140-2 and CC-NDPP.

  • fips-and-cc-ndcpp —This cipher list is compliant with with both FIPS and CC-NDPP certifications.

  • fips-high-security —This cipher list is compliant with FIPS 140-2 certification, and excludes low-security ciphers.

  • cc-ndcpp-high-security —This cipher list is compliant with CC-NDPP certification, and excludes low-security ciphers.

  • fips-and-cc-ndcpp-high-security —This cipher list is compliant with both FIPS and CC-NDPP certifications, and excludes low-security

  • compatible—Improved security that maintains backward compatibility.

  • custom—A user-created cipher list.

To configure the advanced SSL certificate settings:
  1. In the Web UI, choose Settings > SSL Intercept.

  2. Click Advanced SSL Configuration.

  3. Disable Reverse Proxy: By default Reverse Proxy is disabled. Perform step 4 if you want to enable reverse proxy mode, else continue from step 5 onwards.

  4. Enable Reverse Proxy: By default Reverse Proxy is disabled. Use the On/Off toggle to enable it. When the Reverse Proxy mode is enabled, NX intercepts inbound HTTPS connections that are initiated by a client towards a server, when NX is deployed in front of HTTPS Server. This requires server certificate and a private key to decrypt the incoming HTTPS traffic securely.

    1. In the SSL Ports field, enter the TCP port number.

      To add another port, click the circled plus sign and repeat the previous step.

      To delete a port, click X next to the port.

    2. From the Server Certificate list, select the certificate you want to import.

  5. In the SSL Ports field, enter the TCP port number.

    To add another port, click the circled plus sign and repeat the previous step.

    To delete a port, click X next to the port.

  6. In the SSL Trusted Certificate drop-down list, choose the SSL interception certificate that is issued by a trusted public certificate authority (CA) or your own organization.

  7. In the SSL Untrusted Certificate drop-down list, choose the SSL interception certificate that acts as an untrusted certificate.

  8. In the Inbound TLS Minimum Version drop-down list, choose one of the following TLS versions:

    • TLSv1.0

    • TLSv1.1

    • TLSv1.2

    • TLSv1.3

  9. In the Inbound Cipher List drop-down list, choose one of the following cipher lists to associate with an inbound connection:

    • fips

    • cc-ndcpp

    • fips-and-cc-ndcpp

    • fips-high-security

    • cc-ndcpp-high-security

    • fips-and-cc-ndcpp-high-security

    • compatible

    • custom

    The list of inbound SSL ciphers is also displayed.

  10. In the Outbound TLS Minimum Version drop-down list, choose one of the following TLS versions:

    • TLSv1.0

    • TLSv1.1

    • TLSv1.2

    • TLSv1.3

  11. In the Outbound Cipher List drop-down list, choose one of the following cipher lists to associate with an outbound connection:

    • original

    • fips

    • cc-ndcpp

    • fips-and-cc-ndcpp

    • high-security

    • compatible

    • custom

    The list of outbound SSL ciphers is also displayed.

  12. Click Save.