- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-29-2018 10:43 AM
show system setting ssl-decrypt certificate
Certificates for Global
SSL Decryption CERT
global trusted
ssl-decryption x509 certificate
version 2
cert algorithm 4
valid 171204224608Z -- 221204225608Z
cert pki 1
subject: NGFW-2
issuer: Root CA 2
serial number(19)
4f 00 00 00 2b e2 bd d9 f7 cb fa 0b 9a 00 01 00 O...+... ........
00 00 2b ..+
rsa key size 2048 bits siglen 512 bytes
basic constraints extension CA 1
also serves as untrusted certificate
NO INBOUND CERT
Need to know what does no inbound cert mean here?
10-29-2018 10:49 AM
There are two types of SSL decryption policies - inbound decryption and Forward Proxy decryption. It sounds like you have a policy that matched on an inbound decryption policy. This is useful if you are hosting a server (e.g. in a DMZ) and have both the public and private certificates for that SSL/TLS server loaded onto the firewall, and you wish to do an inbound decryption inspection of the traffic.
If you have users trying to visit a website on the internet, you want a forward proxy decryption policy.
Does that help?
10-29-2018 10:49 AM
There are two types of SSL decryption policies - inbound decryption and Forward Proxy decryption. It sounds like you have a policy that matched on an inbound decryption policy. This is useful if you are hosting a server (e.g. in a DMZ) and have both the public and private certificates for that SSL/TLS server loaded onto the firewall, and you wish to do an inbound decryption inspection of the traffic.
If you have users trying to visit a website on the internet, you want a forward proxy decryption policy.
Does that help?
10-29-2018 10:53 AM - edited 10-29-2018 10:53 AM
We are using SSL forward Proxy
Seems that info is for the No Inbound Cer================No inbound SSL decrypt?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!