policymgr ssl-intercept config outbound cipher-list

Prev Next

Configures the cipher list for outbound SSL interception and TLS connections.

For details about how to configure the advanced SSL settings for SSL interception, see the "Configuring SSL Interception" chapter of the Network Security User Guide.

Syntax

policymgr ssl-intercept config outbound cipher-list {original | fips | cc-ndcpp | fips-and-cc-ndcpp | fips-high-security | cc-ndcpp-high-security | fips-and-cc-ndcpp-high-security | compatible | custom}

Parameters

original

Original Trellix cipher list that is used for maximum compatibility.

fips

This cipher list is compliant with the Federal Information Processing Standard (FIPS) 140-2.

cc-ndcpp

This cipher list is compliant with Common Criteria Network Device Protection Profile (CC-NDPP).

fips-and-cc-ndcpp

This cipher list is compliant with FIPS 140-2 and CC-NDPP.

fips-high-security

This cipher list is compliant with FIPS 140-2 and excludes low-security ciphers.

cc-ndcpp-high-security

This cipher list is compliant with CC-NDPP and excludes low-security ciphers.

fips-and-cc-ndcpp-high-security

This cipher list is compliant with both FIPS 140-2 and CC-NDPP and excludes low-security ciphers.

compatible

Improved security that maintains backward compatibility.

custom

A user-created cipher list.

Example

hostname (config) # policymgr ssl-intercept config outbound cipher-list original

The following example shows how to configure FIPS 140-2 compliance for outbound SSL interception and TLS connections.

hostname (config) # policymgr ssl-intercept config outbound cipher-list fips

The following example shows how to configure CC-NDPP compliance for outbound SSL interception and TLS connections.

hostname (config) # policymgr ssl-intercept config outbound cipher-list cc-ndcpp

The following example shows how to configure FIPS 140-2 and CC-NDPP compliance with high security for outbound SSL interception and TLS connections.

hostname (config) # policymgr ssl-intercept config outbound cipher-list fips-and-cc-ndcpp-high-security

The following example shows how to configure the high security setting for outbound SSL interception and TLS connections.

hostname (config) # policymgr ssl-intercept config outbound cipher-list high-security

The following example shows how to configure the compatible setting for outbound SSL interception and TLS connections.

hostname (config) # policymgr ssl-intercept config outbound cipher-list compatible

The following example shows how to configure the custom setting for outbound SSL interception and TLS connections.

hostname (config) # policymgr ssl-intercept config outbound cipher-list custom

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.2.1