policymgr interface <interfacePair> ssl-intercept mirror vlan

Prev Next

Configures a virtual local area network (VLAN) identification number so that the VLAN ID is inserted into the decrypted mirrored packet if the VLAN ID is not present in the original HTTPS traffic.

For details about how to configure the VLAN identification number so that the VLAN ID is inserted into the decrypted mirrored packet, see the "Configuring Threat Management" chapter of the Network Security User Guide.

Syntax

[no] policymgr interface <interfacePair> ssl-intercept mirror vlan <vlanID>

Parameters

no

Use the no form of this command to delete the VLAN identification number from an interface pair.

<interfacePair>

The interface pair that is already configured in inline mode (monitor or block mode) for SSL decryption mirroring.

<vlanID>

The VLAN identification number. The range is from 1 to 4094.

Example

The following example configures the VLAN identification number so that the VLAN ID is inserted into the decrypted mirrored packet:

hostname (config) # policymgr interface A ssl-intercept mirror vlan 545

The following example deletes the VLAN identification number from an interface pair:

hostname (config) # no policymgr interface A ssl-intercept mirror vlan 545

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.3