Upload an Internal Certificate for Inbound Protection

This task discusses how to upload an internal certificate authority when you create a decryption rule that protects outbound connections. You can also upload the internal CA using Objects > Object Management as discussed in Importing a CA Certificate and Private Key.

Before you begin

Make sure you have an internal certificate authority in one of the formats discussed in Internal Certificate Authority Objects.

Procedure


Step 1

Log in to CDO if you haven't already done so.

Step 2

Click Tools & Services > Firewall Management Center > Policies > Access Control > Decryption.

Step 3

Click Create Decryption Policy.

Step 4

Enter a name for the policy in the Name field and an optional description in the Description field.

Step 5

Click the Inbound Connections tab.

Step 6

From the Internal Certificates list, click Add (add icon).

Step 7

Click Upload.

Step 8

Give the internal CA a Name.

Step 9

Paste or browse to locate the certificate and its private key in the provided fields.

Step 10

If the certificate has a password, select the Encrypted check box and enter the password in the adjacent field.

Step 11

Continue creating the decryption policy as discussed in Create a Decryption Policy with Inbound Connection Protection.