To enable Inbound SSL decryption using proxy, you must purchase the license and add it in the Manager. The license required for proxy based SSL decryption is the same for both inbound and outbound.
To enable proxy based inbound SSL decryption, perform the following steps:
Go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → SSL Decryption.
On the Inbound tab, select Decryption Settings tab.
Deselect Inherit Settings to override the settings of the parent domain.
Select the Enable Inbound Decryption checkbox.
.png)
To enable SSL decryption using proxy, select Proxy from the Decryption Method drop-down.
The Proxy Decryption License displays as Present.
Note
The Proxy Decryption License displays as Required if a license is not assigned.
Note
Ensure that the Inbound Proxy Rules has been created for the server you wish to protect.
Click the tooltip of Proxy Decryption License to view the status.
The Proxy Decryption License window opens.
.png)
[Optional] Click Change License or Unassign.
If you click Change License, it redirects you to Proxy Decryption tab, in the Licenses page on the Manager tab.
If you click Unassign, a warning message pops-up, click OK. The current license will be unassigned and the Sensor will operate without a license.
Click Save.
Note
If a valid license is not assigned to a Sensor, a warning The device requires a valid proxy decryption license is displayed in the Deploy Pending Changes page for that particular Sensor. To assign a valid license, see the section Add a license to the Manager.
Note
Reboot of the Sensor is required after you enable inbound SSL decryption for the feature to function. If you have already configured proxy based outbound SSL decryption, the reboot is not required.