SSL Decryption
Encrypted traffic over the world wide web has increased significantly considering the boom of digitization. SSL Policy mainly in any firewall describes how your encrypted traffic is handled.
SSL Policy in firepower has two main objectives
- HTTP Decryption
- Selective blocking of encrypted traffic .
FTD supports two main SSL/TLS encryption decryption method
- Known Key
- Server's private key and certificate is uploaded to FTD.
- Resign
- Server private key is not required.
Defining PKI Objects
Object > Object Management > PKI
- Internal CA
- Needed for "Decrypt Resign"
- Used for outgoing traffic source NAT
- Internal Certificate
- Needed for "Decrypt Known Key" rules
- Used for incoming traffic destination NAT
Comments
Post a Comment