Displays the status of SSL interception on each network port pair.
For details about how to configure SSL interception, see the "Configuring SSL Interception" chapter of the Network Security User Guide.
Syntax
show policymgr ssl-interceptParameters
None
Output fields
The following table describes the output fields for the show policymgr ssl-intercept command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
ssl intercept enable | SSL interception is added to a network port pair. |
ssl intercept interface enable | SSL interception is enabled on a port pair. |
ssl intercept inbound min_version | Minimum TLS version required for inbound SSL interception connections on the port pair. |
ssl intercept inbound cipher list | Cipher list for inbound SSL interception and TLS connections on the port pair. |
ssl intercept inbound trusted cert name | SSL interception certificate that is issued by a trusted public certificate (CA) or your own organization. |
ssl intercept inbound untrusted cert name | SSL interception certificate that acts as an untrusted certificate. |
ssl intercept alpn enable | SSL interception is enabled on ALPN configuration. |
ssl intercept outbound min version | Minimum TLS version required for outbound SSL interception connections on the port pair. |
ssl intercept outbound cipher list | Cipher list for outbound SSL interception and TLS connections on the port pair. |
ssl intercept tcp port | TCP port to intercept HTTPS traffic on one port pair. |
Example
The following example displays the status of SSL interception on a port pair.
hostname # show policymgr ssl-intercept Interface A ssl intercept enable: yes ssl intercept interface enable: yes ssl intercept inbound min_version: TLSv1.2 ssl intercept inbound cipher list: original ssl intercept inbound trusted cert name: ssli ssl intercept inbound untrusted cert name: ssl-untrusted ssl intercept outbound min version: TLSv1.2 ssl intercept outbound cipher list: original ssl intercept tcp port: 443 Interface B ssl intercept enable: no Interface C ssl intercept enable: no Interface D ssl intercept enable: no Interface E ssl intercept enable: no Interface F ssl intercept enable: no
User role
Administrator, Monitor, or Analyst
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 8.2