The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling the SSL interception whitelist using the CLI

Prev Next

You can use the url-category whitelist null-sni enable command to enable the SSL interception whitelist when SNI support between the server and the client is not available.

To whitelist the empty SNI URL category:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Whitelist URLs with an empty SNI URL category.

    hostname (config) # url-category whitelist null-sni enable
  3. View URL entries that were processed and whitelisted after the empty SNI URL category feature was enabled.

    hostname (config) # show url-category stats 
    
        URL lookup                     : Enabled
        Whitelist null url             : Enabled
        Whitelist uncategorized url    : Enabled
        SSL Categorization trend       : Enabled
        FireEye Default Whitelist      : Enabled
        Engine Name                    : SSL Intercept Module
        Total urls processed           : 2158
        Total whitelisted urls         : 119
        Total NULL url                 : 29
        Total Uncategorized url        : 13
  4. View the session logger output after enabling this feature.

    hostname (config) # session-logger enable
    hostname (config) # session-logger ssl enable
    hostname # show session-log ssl continuous

    Dec 14 10:24:21 10.10.10.10 41393 10.10.10.11 443 cs_tls_version:N/A rs_tls_version:N/A cs_cipher_suite:N/A rs_cipher_suite:N/A rs_cert_common_name:N/A action:(ssl-1,whitelisted-1,block-0) s_site_name:N/A error:N/A

For detailed information about the SSL session logger and the log details on SSL flows for SSL interception traffic, see Viewing the connection event logs.