Setting Up Network Traffic Decryption and Inspection

Set up certificate authentication and Vault secrets to decrypt and inspect network traffic.

Vault secrets are used to decrypt and inspect SSL/TLS traffic.

SSL inbound inspection decrypts and inspects inbound SSL/TLS traffic from a client to a targeted network server. For more information on SSL inbound inspection, see SSL Inbound Inspection.

SSL forward proxy decrypts and inspect SSL/TLS traffic from internal users to the web. Only one SSL forward proxy secret is allowed for each firewall policy. For more information on SSL forward proxy, see SSL Forward Proxy,

After you create a firewall policy, you'll create a mapped secret to map the Vault secret to an inbound or outbound SSL key. Then you'll create a decryption profile to control how SSL forward proxy and SSL inbound inspection perform session mode checks, server checks, and failure checks.

For more information about how the certificate is used with a firewall policy, see Creating and Managing Firewall Policies.