The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Task list for managing SSL interception

Prev Next

Important

You must use unique CA or subordinate CA certificate for SSLi trusted certificate configuration. The use of self-signed certificates is not recommended.

The certificate must be different under SSLi trusted and untrusted configuration. When a client attempts to connect to a server in real-time, Network Security appliance intercepts the connection, receives the server's certificate, and verifies if the issuing root or subordinate CA is present in its trusted CA-cert-bundle.

  • If the CA is present in the trusted bundle- The Network Security appliance presents the configured trusted certificate to the client.

  • If the CA cannot be found in the trusted bundle- The Network Security appliance presents the configured untrusted certificate to the client.

Complete the steps for managing SSL interception in the following order:

  1. Verify that the operational mode for inline deployment on a network port pair is configured by using the show policymgr interfaces command. For details about how to configure inline operational modes, see Configuring inline operational modes.

  2. Import the public and private keys for a trusted SSL interception CA certificate and an untrusted SSL interception CA certificate. For details about how to import the SSL CA certificate, see Importing an SSL CA certificate using the Web UI or Importing an SSL interception CA certificate using the CLI.

  3. (Optional) Add a rule to the network policy. For details about how to add a rule to the network policy, see Adding or deleting rules to a network policy for SSL interception using the Web UI or Adding or deleting rules to a network policy for SSL interception using the CLI.

  4. (Optional) Download and install the latest URL categories from the third-party URL categorization database. For details about how to configure automatic URL category updates, see Configuring automatic URL category updates using the CLI. For details about how to force immediate URL category updates, see Forcing immediate URL category updates using the CLI.

  5. (Optional) Add a domain to the built-in custom whitelist category. For details about how to add a domain to the built-in custom whitelist category, see Adding or deleting domains to the custom whitelist category using the Web UI.

    If you want to add a domain to the built-in custom whitelist exception category, see Adding or deleting domains to the custom whitelist exception category using the Web UI.

    You can enable the appliance not to decrypt traffic that matches a domain in the predefined exclusion list. For details, see Enabling or disabling the Trellix whitelist category using the Web UI.

  6. (Optional) Enable SSL interception bypass when SNI support between the server and the client is not available. See Enabling SSL interception whitelist using the CLI.

  7. (Optional) Enable SSL interception bypass for uncategorized third-party URLs. See Enabling the SSL interception whitelist for uncategorized third-party URLs using the CLI.

  8. (Optional) Disable SSL interception URL category whitelist feature. See Enabling or disabling the SSL interception whitelist for URL categorization using the CLI.

  9. Enable SSL interception on at least one network port pair. For details about how to enable SSL interception, see Enabling or disabling SSL interception using the Web UI or Enabling or disabling SSL interception using the CLI.

  10. View the results of infected HTTPS alerts that are related to SSL interception on the Alerts > Alerts > Alerts page in the Web UI. For details about how to view HTTPS alerts for SSL interception, see Viewing HTTPS alert details for SSL interception in the Web UI.