<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic That is one way to decrypt - in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-ips-ssl-decryption/m-p/3093583#M42644</link>
    <description>&lt;P&gt;That is one way to decrypt - typically used for incoming traffic where you own the SSL certificate in question.&lt;/P&gt;
&lt;P&gt;For outbound traffic it's more problematic since you have to have a PKI and a trusted sub-CA type certificate to the FTD device that is both trusted by all of your clients and able to decrypt Internet-bound traffic. Also some sites and applications will not work with this as they use certificate pinning.&lt;/P&gt;
&lt;P&gt;In either case, SSL decryption causes a significant performance hit - about 75-80% - as the current platforms do not decrypt in hardware.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jul 2017 15:21:30 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-07-25T15:21:30Z</dc:date>
    <item>
      <title>Cisco FTD &amp; IPS SSL Decryption</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-ips-ssl-decryption/m-p/3093582#M42643</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;Hoping someone can help shed some light on this, which to be fair may be even more fundamental and not necessarily FTD-related.&lt;/P&gt;
&lt;P&gt;We're still a long way off purchasing a Cisco FTD (4110)&amp;nbsp;but are looking at all the capabilities it has to offer. We have a requirement to provide IPS where the traffic flowing through the box will be encrypted. Am I right in thinking that in order to successfully decrypt the traffic we will need to import onto the FTD the target server's certificate + private key to allow the FTD to effectively as act man-in-the-middle?&lt;/P&gt;
&lt;P&gt;Any other considerations we need to take into account, specifically for this platform, that may cause us issues as it relates to IPS and encrypted traffic?&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-ips-ssl-decryption/m-p/3093582#M42643</guid>
      <dc:creator>Devlin Thornicroft</dc:creator>
      <dc:date>2019-03-10T13:53:28Z</dc:date>
    </item>
    <item>
      <title>That is one way to decrypt -</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-ips-ssl-decryption/m-p/3093583#M42644</link>
      <description>&lt;P&gt;That is one way to decrypt - typically used for incoming traffic where you own the SSL certificate in question.&lt;/P&gt;
&lt;P&gt;For outbound traffic it's more problematic since you have to have a PKI and a trusted sub-CA type certificate to the FTD device that is both trusted by all of your clients and able to decrypt Internet-bound traffic. Also some sites and applications will not work with this as they use certificate pinning.&lt;/P&gt;
&lt;P&gt;In either case, SSL decryption causes a significant performance hit - about 75-80% - as the current platforms do not decrypt in hardware.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 15:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-ips-ssl-decryption/m-p/3093583#M42644</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-25T15:21:30Z</dc:date>
    </item>
  </channel>
</rss>

