You can enable or disable SSL interception on one or more network port pairs by using the Network Security appliance Web UI or CLI:
When you enable SSL interception on at least one network port pair, the Network Security appliance will analyze the encrypted parts of HTTPS traffic. When you disable SSL interception on a network port pair, the appliance will not analyze the encrypted parts of HTTPS traffic. After you have configured the Network Security appliance to generate alerts from HTTPS traffic based on SSL interception, you can view the analysis results on the Alerts > Alerts > Alerts page in the Web UI. For details about how to view the matched HTTPS alerts for SSL interception, see Viewing HTTPS alert details for SSL interception in the Web UI.
Note
SSL interception is disabled by default.
Use the
show ipv6command to verify that IPv6 is enabled on the Network Security appliance before you enable SSL interception. Use theipv6 enablecommand to enable IPv6 on the Network Security appliance. Use thepm process fe_fastpath_mgr restartcommand to restart the Trellix Fastpath Manager before you enable SSL interception. For details about how to enable IPv6 routing, see "Basic Network Configuration" in the Network Security System Administration Guide.
Prerequisites
Administrator or Operator access to the Network Security appliance
Verify that the operational mode for inline deployment on a network port pair is configured by using the
show policymgr interfacescommand. For details about how to configure inline operational modes, see Configuring inline operational modes.You have imported the public and private keys for a trusted SSL interception CA certificate and an untrusted SSL interception CA certificate. For details about how to import the SSL CA certificate, see Importing an SSL CA certificate using the Web UI or Importing an SSL interception CA certificate using the CLI.
You have exported the public key issuer certificate that is trusted by a trusted public CA or that acts as an untrusted certificate. For details about how to export the public key for an SSL CA certificate, see Exporting an SSL CA certificate using the Web UI.
You have configured the inbound and outbound SSL interception connections that are part of the advanced SSL settings. For details about how to configure the advanced SSL settings, see Configuring advanced SSL settings for SSL interception using the Web UI or Configuring advanced SSL settings for SSL interception using the CLI.
(Optional) Download and install the latest URL categories from the third-party URL categorization database. For details about how to configure automatic URL category updates, see Configuring automatic URL category updates using the CLI. For details about how to force immediate URL category updates, see Forcing immediate URL category updates using the CLI.
(Optional) Add a domain to the built-in custom whitelist category. For details about how to add a domain to the built-in custom whitelist category, see Adding or deleting domains to the built-in custom whitelist category using the Web UI.
If you want to add a domain to the built-in custom whitelist exception category, see Adding or deleting domains to the built-in custom whitelist exception category using the Web UI .