Configure Rule-based decryption policy exclusions
This task helps you create exclusions in your decryption policy to prevent decryption of traffic that should remain encrypted for compliance, security, or functional reasons.
This task discusses how to exclude certain types of traffic from decryption. We create Do Not Decrypt rules in your decryption policy for this purpose. The rules are initially enabled only for an outbound decryption policy (a policy that uses the Decrypt - Resign policy action).
Before you begin
You must upload an internal CA certificate for your managed device before you can create a rule-based decryption policy that protects outbound connections. You can do this in any of the following ways:
-
Create an internal CA certificate object by going to and referring to PKI objects.
-
At the time you create this decryption policy.
Follow these steps to configure decryption policy exclusions:
Procedure
Step 1 | Complete the tasks discussed in: | ||||||||
Step 2 | Select the appropriate exclusion options based on your security requirements. The exclusions page provides the following options. All options are enabled for an outbound protection policy (Decrypt - Resign rule action) and disabled for all other decryption policy actions.
This figure shows default options.
| ||||||||
Step 3 | Click Create Policy. This figure shows a sample outbound protection policy.
In the preceding example, the Do Not Decrypt rules corresponding to your choices for rule exclusions are automatically added before the Decrypt - Resign rule. The rule for sensitive URL categories is disabled because, by default, that exclusion is disabled. Had you selected the Bypass decryption for sensitive URL categories check box, the rule would have been enabled. |
What to do next
-
Add rule conditions: Rule-based decryption rule conditions
-
Add a default policy action: default actions
-
Configure logging options for the default action .
-
Set advanced policy properties: advanced options.
-
Associate the decryption policy with an access control policy as described in Associate prefilter, decryption, and identity policies with an access control.
-
Deploy configuration changes.



