The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling SSL interception

Prev Next

You can enable or disable SSL interception on one or more network port pairs by using the Network Security appliance Web UI or CLI:

When you enable SSL interception on at least one network port pair, the Network Security appliance will analyze the encrypted parts of HTTPS traffic. When you disable SSL interception on a network port pair, the appliance will not analyze the encrypted parts of HTTPS traffic. After you have configured the Network Security appliance to generate alerts from HTTPS traffic based on SSL interception, you can view the analysis results on the Alerts > Alerts > Alerts page in the Web UI. For details about how to view the matched HTTPS alerts for SSL interception, see Viewing HTTPS alert details for SSL interception in the Web UI.

Note

SSL interception is disabled by default.

Use the show ipv6 command to verify that IPv6 is enabled on the Network Security appliance before you enable SSL interception. Use the ipv6 enable command to enable IPv6 on the Network Security appliance. Use the pm process fe_fastpath_mgr restart command to restart the Trellix Fastpath Manager before you enable SSL interception. For details about how to enable IPv6 routing, see "Basic Network Configuration" in the Network Security System Administration Guide

.

Prerequisites