Decryption Rulesrule-based decryption rules unsupported features
This reference provides guidance for handling RC4, DES, and TLS 1.3 limitations in the Cisco Firepower System, including configuration requirements for decryption policies when dealing with unsupported cipher suites and interface types.
- RC4 cipher not unsupported
- The Rivest Cipher 4 (also referred to as RC4 or ARC4 cipher is known to have vulnerabilities and is considered unsecure.
- Passive, inline tap mode, and SPAN interfaces not supported
-
TLS/SSL traffic cannot be decrypted on passive, inline tap mode, or SPAN interfaces.