The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Inbound SSL decryption using DHE/ECDHE ciphers

Prev Next

Trellix IPS supported inbound SSL decryption for RSA ciphers. With many users now moving to stronger ciphers suites like DHE (Diffie-Hellman), ECDHE (Elliptic Curve Diffie-Hellman), SSL decryption for these cipher suites is essential. With release 10.1, Trellix IPS performs SSL decryption for DHE/ECDHE ciphers.

When a client sends a request to the server, the Sensor intercepts the traffic and establishes a connection with the server. A McAfee SSL Agent installed on the web server to be protected, sends the session key to the Sensor. The Sensor then uses this key to decrypt the traffic and inspect it before sending the request to the web server.

Note

You can download the McAfee SSL Agent from the Trellix Download Server. The link is available in the SSL Decryption page in the Manager. You can log into the Download Server using your Grant Number. The SSL Agent download file is available under Utilities & Connectors in the Download Server. The web server to be protected should have the Agent installed on it. In case of DHE/ECDHE ciphers suites since the public keys are dynamically generated, the Agent passes the keys to the Sensor every time a new connection is established. When the traffic flows through the Sensor, the keys are already available in the Sensor which helps in inspecting the traffic. When an attack is detected, the Sensor generates an alert in the Manager.

The Agent and the Sensor communicates over the management port for session key exchange. You can specify the number of concurrent connections between the Sensor and Agent in the Manager. The IP address of the web server should be added in the Manager which allows the server to communicate with the Sensor for inbound decryption.

To enable inbound SSL decryption at the admin domain level, go to Devices → <Admin Domain Name> → Global → IPS Device Settings → SSL Decryption.

To enable inbound SSL decryption at the device level, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → SSL Decryption.