Logging Decryptable Connections with TLS/SSLDecryption Rules
Configure logging settings for decryption policy rules to capture and analyze connection events for monitored traffic.
Logging decryptable connections allows you to track and analyze traffic that is being monitored by decryption rules. This is particularly important for security analysis and compliance requirements.
Procedure
Step 1 | In the decryption policy editor, click Edit ( If View ( |
Step 2 | Click Logging. |
Step 3 | Check the Log at End of Connection check box. For monitored traffic, end-of-connection logging is required. |
Step 4 | Specify where to send connection events. Send events to the event viewer if you want to perform Cloud-Delivered Firewall Management Center-based analysis on these connection events. For monitored traffic, this is required. |
Step 5 | Click Save to save the rule. |
Step 6 | Click Save to save the decryption policy. |
Logging is now configured for the decryption rule, and connection events will be captured and sent to the specified destination for analysis.
What to do next
-
Deploy configuration changes.
