Technical Library
|
Support
Working With Encrypted Data
> SSL decryption port mirroring (appliance deployments)
SSL decryption port mirroring (appliance deployments)
The Content Gateway proxy can be configured to decrypt HTTPS traffic for analysis. A port mirroring feature delivers all decrypted HTTPS traffic to a physical network interface. This allows a trusted service device to inspect and analyze the decrypted data for its own purpose. However, the trusted device cannot modify the decrypted traffic and inject it back into the data steam.
Available only when the proxy is hosted on a V10000 appliance, the feature can be enabled and configured using CLI commands.
Important
The mirror port interface should not be connected to a live network.
This feature is supported:
If SSL decryption is enabled.
Using one of the interfaces on the Content Gateway appliance.
For both IPv4 and IPv6.
For both transparent and explicit proxy deployments.
Only decrypted HTTPS traffic is delivered to the mirrored interface. The following SSL traffic is not delivered:
Traffic that is set to bypass decryption
Blocked traffic
Tunneled traffic
See the
TRITION Appliances CLI Guide
for information on configuring port mirroring.
Working With Encrypted Data
> SSL decryption port mirroring (appliance deployments)
Copyright 2016 Forcepoint LLC. All rights reserved.