The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Use cases for inbound SSL using the Agent based method

Prev Next

Below are some use case scenarios for inbound SSL decryption using the Agent method:

Scenario 1: Web server without load balancer

When you enable SSL decryption in the inbound direction, the web servers to which the clients send requests needs protection against malicious requests. This is possible by installing the Agent on the web server to be protected. When a client sends a request to the web server, the Sensor intercepts the traffic. The Agent on the web server exchanges the session key with the Sensor. The Sensor uses these keys to decrypt and inspect the traffic. If the traffic is clean, the web server sends a response to the request. In case of malicious requests an alert is generated in the Manager.

GUID-DF987F27-B1F5-4F42-821D-9B0BCA0C2AA2-low.png

Steps:

  1. The client sends a request to the web server.

  2. The Sensor intercepts the connection.

  3. The Sensor re-establishes the connection with the server through the Agent installed on the server.

  4. The Agent sends the SSL keys to the Sensor through an encrypted channel.

  5. The Sensor inspects the decrypted traffic.

  6. If there are no attacks in the traffic the server responds to the client’s request.

  7. If an attack is detected, the Sensor generates an alert in the Manager.

Scenario 2: Web server with load balancer

The load balancer usually directs the traffic from the client to the required web server. In such cases, the request from the client is directed to the load balancer first. The load balancer then directs the traffic to the required web server. As the request from the client can be malicious, the load balancer needs to be protected. The Agent shares the session keys with the Sensor for decryption must be installed on the load balancer.

When the client sends a request to the web server, the traffic is first directed to the load balancer. The Sensor intercepts the traffic. The Agent on the load balancer exchanges the session key with the Sensor which the Sensor uses to decrypt and inspect the traffic. If the traffic is clean, the load balancer directs the traffic to the web server which then responds to the client’s request. In case of malicious requests an alert is generated in the Manager.

GUID-1959F237-4CF4-4D4B-9232-E8695E10B941-low.png

Steps:

  1. The client sends a request which is directed to the web server through the load balancer.

  2. The Sensor intercepts the connection.

  3. The Sensor re-establishes the connection with the load balancer through the Agent installed on it.

  4. The Agent sends the SSL keys to the Sensor through an encrypted channel.

  5. The Sensor inspects the decrypted traffic.

  6. If there are no attacks in the traffic the server responds to the client’s request.

  7. If an attack is detected, the Sensor generates an alert in the Manager.