Adds or deletes SSL interception on a network port pair.
In inline mode, you can configure the Network Security appliance with one network port pair.
Note
After you add SSL interception to a port pair, you still need to enable SSL interception.
Note
SSL interception is not supported in TAP mode. When SSL interception is already configured on a network port pair, you cannot change the operational mode from inline deployment to TAP deployment.
For details about how to add or delete SSL interception on a port pair, see the "Configuring SSL Interception" chapter of the Network Security User Guide.
Syntax
[no] policymgr interface <port-pair-name> ssl-intercept create
Parameters
no
Use the no form of this command to delete SSL interception from a network port pair.
<port-pair-name>
Designation that is configured on the appliance interface.
Example
The following example adds SSL interception to a network port pair:
hostname (config) # policymgr interface A ssl-intercept create
The following example deletes SSL interception from a network port pair:
hostname (config) # no policymgr interface A ssl-intercept create
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 8.2. The
policymgr interface ssl-intercept createcommand is not available in Release 8.2.1.