Configures a new destination TCP port number to modify the SSL decrypted packet before it is mirrored. This can be useful when you want to send SSL decrypted traffic back to a security device for analysis.
For details about how to change the destination TCP port number in the SSL decrypted packet, see the "Configuring Threat Management" chapter of the Network Security User Guide.
Syntax
[no] policymgr interface <interfacePair> ssl-intercept mirror tcp-port <portNumber>
Parameters
no
Use the no form of this command to delete the destination TCP port number from an interface pair.
<interfacePair>
The interface pair that is already configured in inline mode (monitor or block mode) for SSL decryption mirroring.
<portNumber>
The destination TCP port number.
Example
The following example configures the destination TCP port number to modify the SSL decrypted packet:
hostname (config) # policymgr interface A ssl-intercept mirror tcp-port 456
The following example deletes the destination TCP port number from an interface pair:
hostname (config) # no policymgr interface A ssl-intercept mirror tcp-port 456
User Role
Administrator or Operator
Command Mode
Configuration
Supported Appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 8.3