The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling SSL interception using the CLI

Prev Next

Use the commands in this section to enable or disable SSL interception on one or more network port pairs.

To enable SSL interception on a network port pair:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enable SSL interception on a port pair.

    hostname (config) # policymgr interface<port-pair-name>ssl-intercept enable

    where <port-pair-name> specifies the designation that is configured on the appliance interface.

  3. Repeat the previous step for each port pair on which you want to enable SSL interception.

  4. Save your changes.

    hostname (config) # write memory
  5. Verify the status of SSL interception.

    hostname (config) # show policymgr ssl-intercept
    SSL-Intercept Configuration:
             ssl intercept inbound min_version: TLSv1.0
             ssl intercept inbound cipher list: original
             ssl intercept inbound trusted cert name: SSLi
             ssl intercept inbound untrusted cert name: system-self-signed
             ssl intercept outbound min version: TLSv1.0
             ssl intercept outbound cipher list: compatible
             ssl intercept tcp port: 443
    Interface A
             ssl intercept enable: no
    Interface B
             ssl intercept enable: yes
    Interface C
             ssl intercept enable: yes
    Interface D
             ssl intercept enable: no

    The "ssl intercept enable" line displays "yes" if SSL interception is enabled on each port pair.

To disable SSL interception on a network port pair:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Disable SSL interception on a port pair.

    hostname (config) # no policymgr interface<port-pair-name>ssl-intercept enable

    where <port-pair-name> specifies the designation that is configured on the appliance interface.

  3. Repeat the previous step for each port pair on which you want to disable SSL interception.

  4. Save your changes.

    hostname (config) # write memory
  5. Verify the status of SSL interception.

    hostname (config) # show policymgr ssl-intercept
    SSL-Intercept Configuration:
             ssl intercept inbound min_version: TLSv1.0
             ssl intercept inbound cipher list: original
             ssl intercept inbound trusted cert name: SSLi
             ssl intercept inbound untrusted cert name: system-self-signed
             ssl intercept outbound min version: TLSv1.0
             ssl intercept outbound cipher list: compatible
             ssl intercept tcp port: 443
    Interface A
             ssl intercept enable: no
    Interface B
             ssl intercept enable: no
    Interface C
             ssl intercept enable: yes
    Interface D
             ssl intercept enable: n

    The "ssl intercept enable" line displays "no" if SSL interception is disabled on each port pair.