policymgr interface <interfacePair> ssl-intercept mirror tcp-port

Prev Next

Configures a new destination TCP port number to modify the SSL decrypted packet before it is mirrored. This can be useful when you want to send SSL decrypted traffic back to a security device for analysis.

For details about how to change the destination TCP port number in the SSL decrypted packet, see the "Configuring Threat Management" chapter of the Network Security User Guide.

Syntax

[no] policymgr interface <interfacePair> ssl-intercept mirror tcp-port <portNumber>

Parameters

no

Use the no form of this command to delete the destination TCP port number from an interface pair.

<interfacePair>

The interface pair that is already configured in inline mode (monitor or block mode) for SSL decryption mirroring.

<portNumber>

The destination TCP port number.

Example

The following example configures the destination TCP port number to modify the SSL decrypted packet:

hostname (config) # policymgr interface A ssl-intercept mirror tcp-port 456

The following example deletes the destination TCP port number from an interface pair:

hostname (config) # no policymgr interface A ssl-intercept mirror tcp-port 456

User Role

Administrator or Operator

Command Mode

Configuration

Supported Appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.3