Configures the cipher list for outbound SSL interception and TLS connections.
For details about how to configure the advanced SSL settings for SSL interception, see the "Configuring SSL Interception" chapter of the Network Security User Guide.
Syntax
policymgr ssl-intercept config outbound cipher-list {original | fips | cc-ndcpp | fips-and-cc-ndcpp | fips-high-security | cc-ndcpp-high-security | fips-and-cc-ndcpp-high-security | compatible | custom}
Parameters
original
Original Trellix cipher list that is used for maximum compatibility.
fips
This cipher list is compliant with the Federal Information Processing Standard (FIPS) 140-2.
cc-ndcpp
This cipher list is compliant with Common Criteria Network Device Protection Profile (CC-NDPP).
fips-and-cc-ndcpp
This cipher list is compliant with FIPS 140-2 and CC-NDPP.
fips-high-security
This cipher list is compliant with FIPS 140-2 and excludes low-security ciphers.
cc-ndcpp-high-security
This cipher list is compliant with CC-NDPP and excludes low-security ciphers.
fips-and-cc-ndcpp-high-security
This cipher list is compliant with both FIPS 140-2 and CC-NDPP and excludes low-security ciphers.
compatible
Improved security that maintains backward compatibility.
custom
A user-created cipher list.
Example
hostname (config) # policymgr ssl-intercept config outbound cipher-list original
The following example shows how to configure FIPS 140-2 compliance for outbound SSL interception and TLS connections.
hostname (config) # policymgr ssl-intercept config outbound cipher-list fips
The following example shows how to configure CC-NDPP compliance for outbound SSL interception and TLS connections.
hostname (config) # policymgr ssl-intercept config outbound cipher-list cc-ndcpp
The following example shows how to configure FIPS 140-2 and CC-NDPP compliance with high security for outbound SSL interception and TLS connections.
hostname (config) # policymgr ssl-intercept config outbound cipher-list fips-and-cc-ndcpp-high-security
The following example shows how to configure the high security setting for outbound SSL interception and TLS connections.
hostname (config) # policymgr ssl-intercept config outbound cipher-list high-security
The following example shows how to configure the compatible setting for outbound SSL interception and TLS connections.
hostname (config) # policymgr ssl-intercept config outbound cipher-list compatible
The following example shows how to configure the custom setting for outbound SSL interception and TLS connections.
hostname (config) # policymgr ssl-intercept config outbound cipher-list custom
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 8.2.1