<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to verify SSL decryption in FirePOWER? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-verify-ssl-decryption-in-firepower/m-p/2927986#M1029934</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am trying to inspect incoming SSL traffic in my FirePOWER as I have internal SSL web server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cert and Key are already imported through PKI object management and SSL policy is already created too. However, I am here a bit lost my way to find out the verification where my SSL policy to incoming SSL traffic is working properly or not.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you here tell me where and how to verify it? Thanks much.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;With Love,&lt;/P&gt;
&lt;P&gt;Si Thu&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:04:41 GMT</pubDate>
    <dc:creator>Sithulwin</dc:creator>
    <dc:date>2019-03-12T13:04:41Z</dc:date>
    <item>
      <title>How to verify SSL decryption in FirePOWER?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-verify-ssl-decryption-in-firepower/m-p/2927986#M1029934</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am trying to inspect incoming SSL traffic in my FirePOWER as I have internal SSL web server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cert and Key are already imported through PKI object management and SSL policy is already created too. However, I am here a bit lost my way to find out the verification where my SSL policy to incoming SSL traffic is working properly or not.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you here tell me where and how to verify it? Thanks much.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;With Love,&lt;/P&gt;
&lt;P&gt;Si Thu&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-verify-ssl-decryption-in-firepower/m-p/2927986#M1029934</guid>
      <dc:creator>Sithulwin</dc:creator>
      <dc:date>2019-03-12T13:04:41Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/how-to-verify-ssl-decryption-in-firepower/m-p/2927987#M1029936</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can check the connection events. Enable the SSL filters in SSL policy to see which ssl rule the traffic is hitting and if its being encrypted or no.&lt;/P&gt;
&lt;P&gt;Navigate to analysis&amp;gt; connection events&amp;gt;tables view of connection events.&lt;/P&gt;
&lt;P&gt;Click on any filed cross sign and enable the SSl related fields as shows in screenshot.&lt;/P&gt;
&lt;P&gt;Then you can either filter events based on connection events or see the traffic as it hits that.&lt;/P&gt;
&lt;P&gt;Rate if helps.&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jul 2016 11:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-verify-ssl-decryption-in-firepower/m-p/2927987#M1029936</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-07-17T11:43:23Z</dc:date>
    </item>
    <item>
      <title>Hi Yogdhanu,</title>
      <link>https://community.cisco.com/t5/network-security/how-to-verify-ssl-decryption-in-firepower/m-p/2927988#M1029941</link>
      <description>&lt;P&gt;Hi Yogdhanu,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks much for your guide.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As for inspecting incoming SSL traffic for internal SSL web server, I have created internal cert (for &lt;G class="gr_ gr_9 gr-alert gr_gramm gr_run_anim Grammar only-ins doubleReplace replaceWithoutSep" id="9" data-gr-id="9"&gt;web&lt;/G&gt; server) under PKI object management. And created SSL policy for inbound traffic as the screenshot. Not: I am not going to decrypt to outbound SSL traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you please advise on my SSL whether it is correct particularly for incoming SSL traffic. Many thanks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;With Love,&lt;/P&gt;
&lt;P&gt;Si Thu&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jul 2016 14:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-verify-ssl-decryption-in-firepower/m-p/2927988#M1029941</guid>
      <dc:creator>Sithulwin</dc:creator>
      <dc:date>2016-07-17T14:52:35Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/how-to-verify-ssl-decryption-in-firepower/m-p/2927989#M1029943</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;yes, that is correct settings for only internal web server traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ankita&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 09:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-verify-ssl-decryption-in-firepower/m-p/2927989#M1029943</guid>
      <dc:creator>ankojha</dc:creator>
      <dc:date>2016-07-18T09:20:36Z</dc:date>
    </item>
  </channel>
</rss>

