This URL gets the SSL configuration at the Sensor level for 9.2 NS-series Sensors.
Resource URL
GET /sensor/<sensorId>/decryptionsettings
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| sensor_id | Sensor id | Number | Yes |
Following fields are returned.
| Field Name | Description | Data Type |
|---|---|---|
| inheritSettings | Inherit settings from parent domain | Boolean |
| decryptionState | SSL state. The values can be:
|
String |
| anticipatedSSLTrafficUsageAnticipated | Anticipated inbound SSL traffic usage. The values can be:
|
String |
| maxFlow | Maximum flow allowed in the Sensor. | Number |
| decryptedFlow | Flows allocated to the Sensor. | Number |
| sslInactivityTimeoutInMinutes | The maximum amount of time a Sensor will keep an outbound SSL flow open when no data has been seen on the Sensor. | Number |
| includeDecryptedPCAPS | Include decrypted packets while packet capture. | Boolean |
| enableDhSupport | DH support | Boolean |
| maxConcurrent | Maximum concurrent connection allowed between a Trellix Agent and a Sensor. The value can range from 1 to 1024. | Number |
| permittedIPv4CIDRBlocks | IPv4 CIDR blocks | Object |
| permittedIPv6CIDRBlocks | IPv6 CIDR blocks | Object |
Details of permittedIPv4CIDRBlocks and permittedIPv6CIDRBlocks:
| Field Name | Description | Data Type |
|---|---|---|
| id | ID of CIDR added | Number |
| cidr | CIDR block | String |
Details of failureHandling:
| Field Name | Description | Data Type |
|---|---|---|
| untrustedOrExpiredServerCertificate | Action to take if the target web server's certificate is not on the Sensor's trusted CA list. Used only in case of outbound SSL. The value can be:
|
Number |
Example
Request
GET https://<NSM_IP>/sdkapi/sensor/1001/decryptionsettings
Response
{
"inheritSettings": false,
"decryptionState": "INBOUND",
"anticipatedSSLTrafficUsage": "VERY_HEAVY",
"sslInactivityTimeoutInMinutes": 6,
"maxFlow": 1600000,
"enableDhSupport": true,
"maxConcurrent": 210,
"permittedIPv4CIDRBlocks": [
{
"id": 428,
"cidr": "4.4.4.4/32",
"action": null
},
{
"id": 366,
"cidr": "1.1.1.1/32",
"action": null
}
],
"permittedIPv6CIDRBlocks": [
{
"id": 429,
"cidr": "2001:0DB9:0000:0000:0000:0000:0000:0000/123",
"action": null
},
{
"id": 367,
"cidr": "2001:0DB9:0000:0000:0000:0000:0000:0000/128",
"action": null
}
],
"decryptedFlow": 1600000,
"includeDecryptedPCAPS": true
}
Error Information
Following error codes are returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 404 | 1106 | Invalid Sensor |
| 2 | 500 | 1124 | The Sensor is inactive |
| 3 | 500 | 1001 | Internal error |