show policymgr ssl-intercept

Prev Next

Displays the status of SSL interception on each network port pair.

For details about how to configure SSL interception, see the "Configuring SSL Interception" chapter of the Network Security User Guide.

Syntax

show policymgr ssl-intercept

Parameters

None

Output fields

The following table describes the output fields for the show policymgr ssl-intercept command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

ssl intercept enable

SSL interception is added to a network port pair.

ssl intercept interface enable

SSL interception is enabled on a port pair.

ssl intercept inbound min_version

Minimum TLS version required for inbound SSL interception connections on the port pair.

ssl intercept inbound cipher list

Cipher list for inbound SSL interception and TLS connections on the port pair.

ssl intercept inbound trusted cert name

SSL interception certificate that is issued by a trusted public certificate (CA) or your own organization.

ssl intercept inbound untrusted cert name

SSL interception certificate that acts as an untrusted certificate.

ssl intercept alpn enable

SSL interception is enabled on ALPN configuration.

ssl intercept outbound min version

Minimum TLS version required for outbound SSL interception connections on the port pair.

ssl intercept outbound cipher list

Cipher list for outbound SSL interception and TLS connections on the port pair.

ssl intercept tcp port

TCP port to intercept HTTPS traffic on one port pair.

Example

The following example displays the status of SSL interception on a port pair.

hostname # show policymgr ssl-intercept
Interface A
         ssl intercept enable: yes
         ssl intercept interface enable: yes
         ssl intercept inbound min_version: TLSv1.2
         ssl intercept inbound cipher list: original
         ssl intercept inbound trusted cert name: ssli
         ssl intercept inbound untrusted cert name: ssl-untrusted
         ssl intercept outbound min version: TLSv1.2
         ssl intercept outbound cipher list: original
         ssl intercept tcp port: 443
Interface B
         ssl intercept enable: no
Interface C
         ssl intercept enable: no
Interface D
         ssl intercept enable: no
Interface E
         ssl intercept enable: no
Interface F
         ssl intercept enable: no

User role

Administrator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.2