show system setting ssl-decrypt certificate -----No inbound cert

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

show system setting ssl-decrypt certificate -----No inbound cert

Cyber Elite
Cyber Elite

show system setting ssl-decrypt certificate

 

Certificates for Global

SSL Decryption CERT

global trusted
ssl-decryption x509 certificate
version 2
cert algorithm 4
valid 171204224608Z -- 221204225608Z
cert pki 1
subject: NGFW-2
issuer: Root CA 2
serial number(19)
4f 00 00 00 2b e2 bd d9 f7 cb fa 0b 9a 00 01 00 O...+... ........
00 00 2b ..+
rsa key size 2048 bits siglen 512 bytes
basic constraints extension CA 1
also serves as untrusted certificate

 

NO INBOUND CERT

 

Need to know what does no  inbound cert mean here?

 

 

MP

Help the community: Like helpful comments and mark solutions.
1 accepted solution

Accepted Solutions

L2 Linker

There are two types of SSL decryption policies - inbound decryption and Forward Proxy decryption.  It sounds like you have a policy that matched on an inbound decryption policy.  This is useful if you are hosting a server (e.g. in a DMZ) and have both the public and private certificates for that SSL/TLS server loaded onto the firewall, and you wish to do an inbound decryption inspection of the traffic.

 

If you have users trying to visit a website on the internet, you want a forward proxy decryption policy.

 

Does that help?

 

View solution in original post

2 REPLIES 2

L2 Linker

There are two types of SSL decryption policies - inbound decryption and Forward Proxy decryption.  It sounds like you have a policy that matched on an inbound decryption policy.  This is useful if you are hosting a server (e.g. in a DMZ) and have both the public and private certificates for that SSL/TLS server loaded onto the firewall, and you wish to do an inbound decryption inspection of the traffic.

 

If you have users trying to visit a website on the internet, you want a forward proxy decryption policy.

 

Does that help?

 

We are using SSL forward Proxy

Seems that info is for the No Inbound Cer================No inbound SSL decrypt?

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 2547 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!