Previously, HTTP Response Decompression was supported for gzip compressed traffic only. With this release of 10.1, Trellix IPS supports deflate compressed traffic along with gzip compressed traffic. This improves the performance by reducing the transfer time and bandwidth consumption.
Note the following:
- HTTP Response Decompression is supported for gzip and deflate compressed files only.
- HTTP Response Decompression is disabled by default.
- To enable HTTP Response Decompression, HTTP Response Traffic Scanning must be enabled.
- Advanced malware inspection of decompressed files is not supported.
- This feature is supported only on NS-series.
To enable HTTP Response Decompression, go to Policy → Intrusion Prevention → Policy Types → Inspection Options. Double-click on any inspection policy and select Inspection Options → Traffic Inspection tab. From the HTTP Response Decompression drop-down list, select Inbound only, Outbound only, or Inbound and Outbound.