policymgr interface <interfacePair> ssl-intercept mirror enable

Prev Next

Adds or deletes mirroring of SSL decrypted traffic on the monitoring interface pair.

When you add mirroring of SSL decrypted traffic on at least one monitoring interface pair that is configured for inline deployment, the Network Security appliance will mirror SSL decrypted traffic over the mirror port in tap mode.

When you delete mirroring of SSL decrypted traffic from the monitoring interface pair, the appliance will not mirror or track SSL decrypted traffic to an external device.

For details about how to add or delete mirroring of SSL decrypted traffic on the monitoring interface pair, see the "Configuring Threat Management" chapter of the Network Security User Guide.

Note

SSL decryption mirroring is disabled by default.

Note

If you want the Network Security appliance to mirror or track SSL decrypted traffic to an external device, you must enable SSL interception on a network port pair. For details about how to enable SSL interception, see the "Configuring SSL Interception" chapter of the Network Security User Guide.

Syntax

[no] policymgr interface <interfacePair> ssl-intercept mirror enable

Parameters

no

Use the no form of this command to delete mirroring of SSL decrypted traffic from an interface pair.

<interfacePair>

The interface pair that is already configured in inline mode (monitor or block mode) for SSL decryption mirroring and the mirror port is in tap mode.

Example

The following example adds mirroring of SSL decrypted traffic on the monitoring interface pair:

hostname (config) # policymgr interface C ssl-intercept mirror enable

The following example deletes mirroring of SSL decrypted traffic from an interface pair:

hostname (config) # no policymgr interface C ssl-intercept mirror enable

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.3