By default, the Network Security appliance processes traffic collectively, regardless of the port that received the traffic. If the Network Security appliance receives the encrypted and decrypted versions of the same stream, they might not be collected properly.
You must ensure that different VLAN tags are configured on the encrypted and decrypted streams.
On the NX 300 models, use the policymgr session interface enable command to have the appliance receive decrypted SSL traffic on a different interface.
On the NX 400 models and above, you must also add a VLAN tag to decrypted traffic that arrives on a different port pair to allow the appliance to analyze traffic.
Administrator access to the Network Security appliance.