<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco FTD Inline Set SSL decryption support in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4908348#M1103599</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We are planning to deploy a pair of FTD appliances for one of our customer. We will be running routed mode and will use inline sets for the connectivity. The customer wants to configure SSL decryption for both inbound (for published services) and outbound traffic (for user internet browsing). Please let me know whether there are any limitations for SSL decryption when we use inline sets.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Shabeeb&lt;/P&gt;</description>
    <pubDate>Sun, 20 Aug 2023 03:22:08 GMT</pubDate>
    <dc:creator>SHABEEB KUNHIPOCKER</dc:creator>
    <dc:date>2023-08-20T03:22:08Z</dc:date>
    <item>
      <title>Cisco FTD Inline Set SSL decryption support</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4908348#M1103599</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We are planning to deploy a pair of FTD appliances for one of our customer. We will be running routed mode and will use inline sets for the connectivity. The customer wants to configure SSL decryption for both inbound (for published services) and outbound traffic (for user internet browsing). Please let me know whether there are any limitations for SSL decryption when we use inline sets.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Shabeeb&lt;/P&gt;</description>
      <pubDate>Sun, 20 Aug 2023 03:22:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4908348#M1103599</guid>
      <dc:creator>SHABEEB KUNHIPOCKER</dc:creator>
      <dc:date>2023-08-20T03:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Inline Set SSL decryption support</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4908368#M1103600</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Check this document :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/623/fdm/fptd-fdm-config-guide-623/fptd-fdm-ssl-decryption.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/623/fdm/fptd-fdm-config-guide-623/fptd-fdm-ssl-decryption.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Aug 2023 06:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4908368#M1103600</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-08-20T06:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Inline Set SSL decryption support</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4908378#M1103603</link>
      <description>&lt;P&gt;adding to other comment- Make sure you sizing the hardware is correct depends on the traffic going in and out.&lt;/P&gt;
&lt;P&gt;our case enabling the cache added more performance.&lt;/P&gt;
&lt;P&gt;i suggest below good documents and understand the flows. (i used below guide to setup one)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/BRKSEC-3063.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/BRKSEC-3063.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=Ra52ulwoVvY" target="_blank"&gt;https://www.youtube.com/watch?v=Ra52ulwoVvY&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Aug 2023 06:48:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4908378#M1103603</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-08-20T06:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Inline Set SSL decryption support</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4908463#M1103619</link>
      <description>&lt;P&gt;Thanks guys for the response. I have enabled SSL interception for FTDs with L3 interfaces in the past.&lt;/P&gt;
&lt;P&gt;Actually in our current case our FTDs will not have L3 interfaces except the management interface. We will have only inline sets which are like bump-in-the-wire. So is there any issue in enabling SSL interception for outbound and inbound traffic?.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Aug 2023 15:35:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4908463#M1103619</guid>
      <dc:creator>SHABEEB KUNHIPOCKER</dc:creator>
      <dc:date>2023-08-20T15:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Inline Set SSL decryption support</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4910615#M1103730</link>
      <description>&lt;P&gt;Any update on the above query Guys?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 12:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4910615#M1103730</guid>
      <dc:creator>SHABEEB KUNHIPOCKER</dc:creator>
      <dc:date>2023-08-23T12:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Inline Set SSL decryption support</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4910658#M1103735</link>
      <description>&lt;LI-CODE lang="markup"&gt;Actually in our current case our FTDs will not have L3 interfaces except the management interface. We will have only inline sets which are like bump-in-the-wire. So is there any issue in enabling SSL interception for outbound and inbound traffic?.&lt;/LI-CODE&gt;
&lt;P&gt;When it was Layer 3 configured is this working ?&amp;nbsp; check the Guide lines for bump-in-the-wire (not that we have deployed - so no comments)&lt;/P&gt;
&lt;P&gt;this is cisco community, if this is effecting your environment always reach TAC is best option.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 13:38:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4910658#M1103735</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-08-23T13:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Inline Set SSL decryption support</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4910718#M1103748</link>
      <description>&lt;P&gt;I can't find any reference in the configuration guide saying so, but I don't think SSL decryption will work with an inline set.&lt;/P&gt;
&lt;P&gt;The firewall needs to act as a man in the middle and terminate the SSL session to inspect and then re-sign it. Since it is not in the path IP-wise it cannot do that.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 15:21:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4910718#M1103748</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-08-23T15:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Inline Set SSL decryption support</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4910739#M1103752</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;I had the same doubt and that is the primary reason why I started the Thread. Anyway I am trying to check it internally with Cisco and get the confirmation. I will update once I get a response from them.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Shabeeb&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 15:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-inline-set-ssl-decryption-support/m-p/4910739#M1103752</guid>
      <dc:creator>SHABEEB KUNHIPOCKER</dc:creator>
      <dc:date>2023-08-23T15:51:05Z</dc:date>
    </item>
  </channel>
</rss>

