Prerequisite: To enable proxy based outbound SSL decryption, you must purchase the license and add it in the Manager. The license required for proxy based SSL decryption is the same for both inbound and outbound.
To enable proxy based outbound SSL decryption, perform the following steps:
Note
From 11.1.5.122, jumbo frame traffic with SSL encryption will be decrypted when SSL decryption is enabled.
Go to Devices → <Admin Domain Name> → Global → IPS Device Settings → SSL Decryption.
On the Outbound tab, select Decryption Settings tab.
.png)
Select the Enable Outbound Decryption checkbox.
.png)
Select the required action from the Untrusted/Expired Server Certificate drop-down.
The reasons for failure can be due to the Sensor not being able to validate the web server's certificate. This happens when the certificate signed by a CA is not on the Sensor's trusted CA list.
The descriptions for the possible Sensor actions in case of a failure are as follows:
Action
Description
Decrypt
The Sensor decrypts the flows from the web server.
Block Flow
The Sensor blocks the flows from the web server.
Click Save.
Note
If a valid license is not assigned to a Sensor, a warning The device requires a valid proxy decryption license is displayed in the Deploy Pending Changes page for that particular Sensor. To assign a valid license, see section Add a license to the Manager.
If you change the mode of operation for SSL decryption, or disable SSL decryption, a reboot of the Sensor is required.
Note
Reboot of the Sensor is required after you enable outbound SSL decryption for the feature to function. If you have already configured proxy based inbound SSL decryption, reboot is not required.
Go to, Manager → <Admin Domain Name> → Troubleshooting → Logs → Faults.
View the critical messages for the corresponding Sensor to see if a Sensor reboot is required.
If yes, perform a full reboot of the Sensor.