You can exclude flows from decryption by adding it to the SSL decryption exclusion list. This helps to avoid decrypting personal and sensitive information. It also helps in Sensor performance optimization by reducing the load on the Sensor. This is achieved by avoiding decryption of trusted sessions. You can exclude certain outbound SSL traffic from decryption based on source or destination IP address, destination domain name, and URL category.
Note
SSL decryption exclusions only apply to outbound SSL decryption until version 11.1.5.122. From the 11.1 Update 8 release, SSL decryption exclusions apply to both inbound and outbound SSL decryption.
From the 11.1 Update 8 release, "Outbound" Block Flow configuration applies to both inbound and outbound SSL decryption. It may block inbound flow if an internal web server uses expired/untrusted CA certificates. Thus, an exception rule with the specific internal web server IP should be added to allow inbound flow without decryption when block flow is configured.
To manage SSL decryption exclusions, select Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → SSL Decryption Exclusions. The SSL Decryption Exclusions page is displayed.
The list on the SSL Decryption Exclusions page displays the following information:
Field | Description |
|---|---|
State | Specifies whether the state of the exclusion is Enabled or Disabled. |
Name | Name of the SSL decryption exclusion. |
Scope | Device to which the SSL decryption exclusion is applied. |
Source Endpoint | Specifies the source IP address. |
Destination | Endpoint — Specifies the IP address or domain name of the destination endpoint. URL Hostname — Specifies the destination hostname of the URL. URL Category — Specifies the URL category of the destination endpoint. The Manager retrieves the list of URL categories from the GTI server. |
Last Updated | Time — Specifies the time when the exclusion was last modified. By — Displays the user who modified the exclusion. |
Comment | Additional comment specified for the exclusion. |
Search | Type your search criteria in the field to find the exclusion. |
You can perform the following actions from this page:
Option | Definition |
|---|---|
![]() | Add SSL decryption exclusion. |
![]() | Copy SSL decryption exclusion. |
![]() | Delete SSL decryption exclusion. |
View or Edit | To view or edit an SSL decryption exclusion object, double-click the row of the exclusion. |
Save as CSV | Export the SSL decryption exclusion in CSV format. |
.png)
.png)
.png)
.png)