Create a rule-based decryption policy with other rule actions
Create and manage decryption policies in the Secure Firewall Management Center to control encrypted traffic actions, such as Do Not Decrypt, Block, Block With Reset, or Monitor.
To create a decryption rule with a Do Not Decrypt, Block, Block With Reset, or Monitor rule action, create a decryption policy and edit the policy to add the rule.
When you create a rule-based decryption policy , you can create multiple rules at the same time, including multiple Decrypt - Known Key rules, and multiple Decrypt - Resign rules.
If you enabled Change Management, you must create and assign a ticket before you can create a decryption policy. Before the decryption policy can be used, the ticket and all associated objects (like certificate authorities) must be approved. For more information, see Create change management tickets and Policies and objects that support change management.
Procedure
Step 1 | Log in to Security Cloud Control if you haven't already done so. |
Step 2 | Click and choose . |
Step 3 | Perform these actions: |
Step 4 | Click Edit ( |
Step 5 | Click Add Rule. |
Step 6 | Click Save. |
What to do next
-
Add rule conditions: Rule-based decryption rule conditions
-
Add a default policy action: default actions
-
Configure logging options for the default action as described in .
-
Set advanced policy properties: advanced options.
-
Associate the decryption policy with an access control policy as described in Associate prefilter, decryption, and identity policies with an access control.
-
Deploy configuration changes.