Incoming traffic decryption

Incoming traffic decryption protects internal servers from external attacks by intercepting and decrypting SSL/TLS encrypted traffic before it reaches the protected network.

Decryption policy requirements

This information applies only to rule-based decryption policies and rules

Note

The Firepower System does not support mutual authentication; that is, you cannot upload a client certificate to the Cloud-Delivered Firewall Management Center and use it for Decrypt - Resign, Decrypt - Replace Cert, or Decrypt - Known Key decryption rule actions.

Inbound decryption types

There are two types of inbound decryption:

  • Replace Cert (default): Uses a certificate and key defined in the decryption rule to decrypt traffic. This certificate and key can be the internal server's certificate or a different certificate. You can change the certificate and key at any time. You can replace the certificate in any of the these ways:

    We recommend you include the certificate authority chain.

  • Known Key: Use the internal server's certificate to decrypt incoming traffic. In the event the certificate changes, you must manually update it and consequently interrupt decryption until the new certificate is in place, both in the decryption policy and on the server.