Known key decryption for incoming traffic
The Decrypt - Known Key decryption rule action uses a server's private key to decrypt traffic. The Decrypt - Known Key rule action is used with incoming traffic, where the destination server is inside your protected network.
The main purpose of decrypting with a known key is to protect your servers from external attacks.
Prerequisites and requirements
To use the Decrypt - Known Key rule action, you must create an internal certificate object using the server's certificate file and paired private key file.
Note | The Firepower System does not support mutual authentication; that is, you cannot upload a client certificate to the Security Cloud Control and use it for Decrypt - Resign, Decrypt - Replace Cert, or Decrypt - Known Key decryption rule actions. |