The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Decrypting inbound SSL traffic

Prev Next

Web servers are prone to attacks as there are multiple requests coming to the server from various clients. It becomes difficult to track the requests especially when it is over a secure channel like SSL. Most web servers now use the secure channel for its connections. They use a secure form of HTTP called HTTPS. With HTTPS, security devices have a tough time inspecting the packets. It is even more a reason to decrypt the traffic as attackers can use this channel for initiating attacks. Web servers must be protected from untrusted client connections coming from internet or intranet.

The Sensors intercepts the traffic from the client to the server. All connections to the Sensor are considered inbound as the Sensors are deployed to protect the server. The Sensor decrypts the traffic and inspects it establishing a secure connection between the client and server.

In case of inbound SSL traffic, the Trellix IPS SSL functionality decrypts the traffic in three ways depending on the cipher suite used:

  1. RSA ciphers (Known key method)

  2. DHE, ECDHE, and RSA ciphers (Shared key method/Agent based method)

  3. Proxy method