The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Steps involved in configuring SSL decryption

Prev Next

At a high-level the following are the steps to configure a Sensor to decrypt and inspect SSL traffic:

  1. Enable SSL decryption on the required Sensors and configure Sensor SSL parameters.

  2. SSL decryption is by three methods:

    1. For Agent based method — Select the Enable Diffie-Helman Support checkbox to enable decryption. In the Agent based method, install the Agent on the web servers to be protected.

      Note

      Agent based method is not supported for AWS, Azure and GCP cloud platforms.

    2. For the Known key method — Import the private SSL certificates of the corresponding web servers into the Manager. The Sensors subsequently download these certificates from the Manager.

    3. For Proxy based method — The Sensor acts as a proxy between the client and the server. The Sensor intercepts the client request and forwards the request to the server as the client. Based on the rule configured the Sensor decrypts and scans the traffic.

Note

  • Various fault messages are raised in the Manager related to SSL decryption. For example, an imported SSL certificate might have become invalid or you might have modified SSL configuration settings that requires a Sensor reboot. All these fault messages are explained in detail in the System fault messages.

  • After you install the Agent on a virtual machine, the VM will auto reboot.