Create a rule-based decryption policy with outbound connection protection
This task creates a decryption policy that protects outbound connections by intercepting and decrypting SSL/TLS traffic between internal clients and external servers, then re-encrypting the traffic with an internal CA certificate.
This task discusses how to create a decryption policy with a rule that protects outbound connections; that is, the destination server is outside your protected network. This type of rule has a Decrypt - Resign rule action.
When you create a decryption policy, you can create multiple rules at the same time, including multiple Decrypt - Known Key rules and multiple Decrypt - Resign rules.
If you enabled Change Management, you must create and assign a ticket before you can create a decryption policy. Before the decryption policy can be used, the ticket and all associated objects (like certificate authorities) must be approved. For more information, see Create change management tickets and Policies and objects that support change management.
Before you begin
You can optionally must upload or generate an internal CA certificate for your managed device before you can create a decryption policy that protects outbound connections. You can do this in any of the following ways:
-
Create an internal CA certificate object by going to and referring to PKI objects.
-
At the time you create this decryption policy.
Follow these steps to create a rule-based decryption policy with outbound connection protection:
Procedure
Step 1 | Log in to Security Cloud Control if you haven't already done so. |
Step 2 | Click and choose . |
Step 3 | Click Create Decryption Policy. |
Step 4 | Give the policy a unique Name and, optionally, a Description. The following characters are not supported in decryption policy names:
|
Step 5 | Click the Outbound Connections tab.
|
Step 6 | From the Internal CA list, upload or choose certificates for the rules. For more information about internal certificates, see Generate an internal CA for outbound protection and Upload an internal CA for outbound protection. |
What to do next
-
Add rule conditions: Rule-based decryption rule conditions
-
Add a default policy action: default actions
-
Configure logging options for the default action .
-
Set advanced policy properties: advanced options.
-
Associate the decryption policy with an access control policy as described in Associate prefilter, decryption, and identity policies with an access control.
-
Deploy configuration changes.

