To enable Inbound SSL decryption using proxy, you must purchase the license and add it in the Manager. The license required for proxy based SSL decryption is the same for both inbound and outbound.
Important
If you enable or disable proxy based SSL decryption on a Sensor, you must reboot the Sensor for the changes to take effect. You can opt for a hitless or full reboot.
For NS-series Sensors, you must do a full reboot as hitless reboot is not supported when SSL decryption is enabled.
To enable proxy based inbound SSL decryption, perform the following steps:
Select Devices → <Admin Domain Name> → Global → IPS Device Settings → SSL Decryption.
On the Inbound tab, select Decryption Settings tab.
.png)
Select the Enable Inbound Decryption checkbox.
From the Decryption Method drop-down, select Proxy.
.png)
Click Save.
Note
If a valid license is not assigned to a Sensor, a warning The device requires a valid proxy decryption license is displayed in the Deploy Pending Changes page for that particular Sensor. To assign a valid license, see the section Add a license to the Manager.
Note
Reboot of the Sensor is required after you enable outbound SSL decryption for the feature to function. If you have already configured proxy based inbound SSL decryption, the reboot is not required.