cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2311
Views
2
Helpful
0
Comments
Meddane
VIP
VIP

On Cisco Firepower Threat Defense there are two ways to do SSL Decryption (two actions in the SSL Policy).

Decrypt-Resign: for outbound connection (from an inside PC to an external server).

  • Used for traffic to external servers
  • FTD splits the original session into two: client<--->FTDw<--->server
  • The original server certificate is modified and resigned by FTD

Decrypt-Known-Key: for inbound connection (from an external PC to your internal server).

  • Used for traffic coming to your internal servers
  • Server's Private Key is uploaded to FTD
  • FTD decrypts the client-server taffic on the fly

For both option, ,need to import the right certificates.

How and where?

On FMC:

Navigate to Object --> Object Management --> PKI

There are two options:

Internal CA

  • Internal CA's certifcate (or FTD as CA) and Keys
  • Needed for "Decrypt Resign"

Internal Certificate:

  • Your server's certificate and private key
  • Needed for "Decrypt Known Key"

SSL Dec.PNG

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: