The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage exclusions to outbound SSL flows

Prev Next

You can exclude flows from decryption by adding it to the SSL decryption exclusion list. This helps to avoid decrypting personal and sensitive information. It also helps in Sensor performance optimization by reducing the load on the Sensor. This is achieved by avoiding decryption of trusted sessions. You can exclude certain outbound SSL traffic from decryption based on source or destination IP address, destination domain name, and URL category.

Note

  • SSL decryption exclusions only apply to outbound SSL decryption until version 11.1.5.122. From the 11.1 Update 8 release, SSL decryption exclusions apply to both inbound and outbound SSL decryption.

  • From the 11.1 Update 8 release, "Outbound" Block Flow configuration applies to both inbound and outbound SSL decryption. It may block inbound flow if an internal web server uses expired/untrusted CA certificates. Thus, an exception rule with the specific internal web server IP should be added to allow inbound flow without decryption when block flow is configured.

To manage SSL decryption exclusions, select Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → SSL Decryption Exclusions. The SSL Decryption Exclusions page is displayed.

The list on the SSL Decryption Exclusions page displays the following information:

Field

Description

State

Specifies whether the state of the exclusion is Enabled or Disabled.

Name

Name of the SSL decryption exclusion.

Scope

Device to which the SSL decryption exclusion is applied.

Source Endpoint

Specifies the source IP address.

Destination

Endpoint — Specifies the IP address or domain name of the destination endpoint.

URL Hostname — Specifies the destination hostname of the URL.

URL Category — Specifies the URL category of the destination endpoint. The Manager retrieves the list of URL categories from the GTI server.

Last Updated

Time — Specifies the time when the exclusion was last modified.

By — Displays the user who modified the exclusion.

Comment

Additional comment specified for the exclusion.

Search

Type your search criteria in the field to find the exclusion.

You can perform the following actions from this page:

Option

Definition

GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png

Add SSL decryption exclusion.

GUID-717A81EC-A913-4C2F-B61C-0129ED30387A-low.png

Copy SSL decryption exclusion.

GUID-9A719AD5-F6BE-4CD4-9311-CC6655DF9B70-low.png

Delete SSL decryption exclusion.

View or Edit

To view or edit an SSL decryption exclusion object, double-click the row of the exclusion.

Save as CSV

Export the SSL decryption exclusion in CSV format.

SSL decryption exclusions
SSL decryption exclusions