The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Outbound SSL decryption

Prev Next

With many web servers in the world today, accessing a secure server is important to avoid attacks. When a client sends a request to the server, the server has to be legitimate in order to avoid attacks.

With outbound SSL decryption, when a client sends a request to the server, the Sensor intercepts the traffic and forwards the request to the server. The server then sends its certificate to the Sensor for validation. The Sensor validates the certificate against the list of its trusted CA certificates. Once the server certificate is validated by the Sensor, the Sensor uses its re-signing certificate to establish a secure connection with the client. You can configure the failure handling for flows when the Sensor cannot validate a server certificate.

To enable outbound SSL decryption at the domain level, go to Devices → <Admin Domain Name> → Global → IPS Device Settings → SSL Decryption.

To enable outbound SSL decryption at the device level, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → SSL Decryption.