The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring rules for a network policy for SSL interception

Prev Next

You can configure the rules for a network policy based on the IP address and mask using Classless Inter-Domain Routing (CIDR) notation for SSL interception by using the Network Security appliance Web UI or CLI:

When you configure rules for a network policy on the Network Security appliance, you can control which traffic to decrypt or whitelist based on the destination IPv4 or IPv6 address, source IPv4 or IPv6 address, or mask in CIDR format. You can configure rules for a specified network port pair or all network port pairs. By default, the Network Security appliance can decrypt HTTPS traffic based on any IPv4 or IPv6 address and mask on all port pairs. You can configure multiple network policy rules with different subnets for your organization. The network policy rule allows you to bypass traffic on one port pair and decrypt HTTPS traffic for the same subnet on another port pair. If a subnet is configured on all the port pairs for a network policy rule, the same subnet cannot be used on a specified port pair for another rule.

You enter each rule separately. You can add up to 512 rules to the network policy. The network policy rules are optional.

You can use both IPv4 and IPv6 addresses in rules.

Note

If you deploy the ether1 and ether2 management interfaces so that traffic flows through the port pair configured with SSL interception, and port 443 is configured to intercept HTTPS traffic, you must create a network policy rule to whitelist the IP address and mask of each management interface. Otherwise, SSL interception can interfere with communication on port 443.

Usage guidelines

Trellix recommends that you follow these usage guidelines when you configure rules for a network policy based on the IP address and mask for the network port pair:

  • When no rule is configured for a network policy and SSL interception is enabled on a network port pair, all traffic is decrypted by default.

  • When a set of IP addresses is configured for decryption and URLs using the same addresses are whitelisted, the URLs are not decrypted but are whitelisted.

  • If none of the rules that you configured for a network policy based on CIDR match the incoming source IPv4 or IPV6 address or destination IPv4 or IPv6 address, traffic is decrypted by default.

  • You cannot use a wildcard when configuring rules for a network policy.

  • SSL interception is supported for single-tagged and double-tagged virtual local area network (VLAN) traffic. SSL traffic will not be intercepted if more than two VLAN tags are used.

    Use the policymgr interface <port-pair-name> qinq evlan enable command to optimize maximum SSL interception throughput performance to load balance Q-in-Q traffic. Use the policymgr interface <port-pair-name> re-configure command to reapply the configuration to the specified interface.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • Verify that the operational mode for inline deployment on a network port pair is configured by using the show policymgr interfaces command. For details about how to configure inline operational modes, see Configuring inline operational modes.