<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower SSL decrypt - What ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-ssl-decrypt-what/m-p/4943007#M1105175</link>
    <description>&lt;P&gt;It all depends on security requirement, if you like to go ahead and decrypt the traffic, you have stage level my monitoring the CPU level. (most of the model documentation show you what kind of traffic can handle those boxes) that is part of sizing guide.&lt;/P&gt;
&lt;P&gt;you can also choose what site you like to decrypt and souce IP also.&lt;/P&gt;
&lt;P&gt;tuning tips :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="balajibandi_0-1697633250076.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/199966iDCA2124213E86FF4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="balajibandi_0-1697633250076.png" alt="balajibandi_0-1697633250076.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Oct 2023 12:47:45 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2023-10-18T12:47:45Z</dc:date>
    <item>
      <title>Firepower SSL decrypt - What ?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decrypt-what/m-p/4942950#M1105173</link>
      <description>&lt;P&gt;Hello Everyone&lt;/P&gt;&lt;P&gt;We have a fleet of FTD's and some ASA's that's being phased out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have SSL decrypt working and have successfully tried all the functionality and it works as expected. But now I am wondering in networks with several thousand users and devices what is it worth to decrypt with security/maleware in mind ? Im also thinking that one must be carefull regarding CPU usage and so on.&lt;/P&gt;&lt;P&gt;Thanks in advance for any insight on this.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 11:50:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decrypt-what/m-p/4942950#M1105173</guid>
      <dc:creator>Jon Are Endrerud</dc:creator>
      <dc:date>2023-10-18T11:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SSL decrypt - What ?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decrypt-what/m-p/4943007#M1105175</link>
      <description>&lt;P&gt;It all depends on security requirement, if you like to go ahead and decrypt the traffic, you have stage level my monitoring the CPU level. (most of the model documentation show you what kind of traffic can handle those boxes) that is part of sizing guide.&lt;/P&gt;
&lt;P&gt;you can also choose what site you like to decrypt and souce IP also.&lt;/P&gt;
&lt;P&gt;tuning tips :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="balajibandi_0-1697633250076.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/199966iDCA2124213E86FF4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="balajibandi_0-1697633250076.png" alt="balajibandi_0-1697633250076.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 12:47:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decrypt-what/m-p/4943007#M1105175</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-10-18T12:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SSL decrypt - What ?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decrypt-what/m-p/4943053#M1105176</link>
      <description>&lt;P&gt;The traffic not immediately decrypt and not all traffic decrypt.&lt;/P&gt;
&lt;P&gt;The traffic must pass prefilter and acp then white/blacklist before it decrypt.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 13:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decrypt-what/m-p/4943053#M1105176</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-10-18T13:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SSL decrypt - What ?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ssl-decrypt-what/m-p/4943236#M1105185</link>
      <description>&lt;P&gt;It's rarely possible to decrypt outgoing traffic due to the need to decrypt and re-sign everything which requires having a Certificate Authority that all your user computers trust as a root / signing CA. Plus, even if you have that, may web sites and applications will not allow it due to things like HSTS and certificate pinning. There are better methods to protect your users and traffic.&lt;/P&gt;
&lt;P&gt;Incoming traffic to servers you host is generally more amenable to decryption and is a good option since it allows you to see the plain text contents of traffic destined for your servers and more effectively scan for indications of compromise and attacks.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 12:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ssl-decrypt-what/m-p/4943236#M1105185</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-02-28T12:24:43Z</dc:date>
    </item>
  </channel>
</rss>

