set ssl-inspection policy

In the R82.00.X releases, this command is available starting from the R82.00.00 version.

Description

Configure SSL Inspection policy.

Syntax

set ssl-inspection policy [ mode <mode> ] [ log-policy-bypass-traffic <log-policy-bypass-traffic> ] [ log-inspected-traffic <log-inspected-traffic> ] [ bypass-health-category-traffic <bypass-health-category-traffic> ] [ bypass-government-and-military-category-traffic <bypass-government-and-military-category-] [ bypass-banking-category-traffic <bypass-banking-category-traffic>] [ bypass-other-categories-traffic <bypass-other-categories-traffic> ] [ bypass-streaming-category-traffic <bypass-streaming-category-traffic> ] [ bypass-trusted-wireless-ssl-inspection <bypass-trusted-wireless-ssl-inspection> ] [ bypass-untrusted-wireless-ssl-inspection <bypass-untrusted-wireless-ssl-inspection> ] [ bypass-well-known-update-services <bypass-well-known-update-services> ]

Parameters

Parameter

Description

bypass-banking-category-traffic

Bypass banking category traffic

Type: Boolean (true/false)

bypass-government-and-military-category-traffic

Bypass government category traffic

Type: Boolean (true/false)

bypass-health-category-traffic

Bypass health category traffic

Type: Boolean (true/false)

bypass-other-categories-traffic

Bypass other categories traffic

Type: Boolean (true/false)

bypass-streaming-category-traffic

Bypass streaming category traffic

Type: Boolean (true/false)

bypass-trusted-wireless-ssl-inspection

Bypass SSL inspection on trusted wireless networks

Type: Boolean (true/false)

bypass-untrusted-wireless-ssl-inspection

Bypass SSL inspection on untrusted wireless networks

Type: Boolean (true/false)

bypass-well-known-update-services

Bypass HTTPS Inspection of traffic to well known software update services

Type: Boolean (true/false)

log-inspected-traffic

Generates an SSL inspection log. You can see the logs of the security policy that is enforced on SSL traffic without enabling this feature.

Type: Boolean (true/false)

log-policy-bypass-traffic

Generate an SSL bypass log for SSL traffic that was not inspected by SSL inspection

Type: Boolean (true/false)

mode

Indicates if SSL inspection feature is active

Type: Boolean (true/false)

Example Command

set ssl-inspection policy mode true log-policy-bypass-traffic true log-inspected-traffic true bypass-health-category-traffic true bypass-government-and-military-category-traffic true bypass-banking-category-traffic true bypass-other-categories-traffic true bypass-streaming-category-traffic true bypass-trusted-wireless-ssl-inspection true bypass-untrusted-wireless-ssl-inspection true bypass-well-known-update-services true