SonicOS 7.0 DPI-SSL

Configuring Exclusions and Inclusions by Common Name

You can add trusted domain names to the exclusion list. Adding trusted domains to the Built-in exclusion database reduces the CPU effect of DPI-SSL and prevents the appliance from reaching the maximum number of concurrent DPI-SSL inspected connections.

From Common Name section, you can:

  • View the list of default common names excluded from DPI-SSL inspection.
  • Reject or Approve the default common names.
  • Add custom trusted domain names to:
    • Exclusion list.
    • Skip CFS Category-based Exclusion list.
    • Skip authenticating the server list.

      Opt-out of authenticating the server for this domain if authenticating the server results in the connection being blocked. Enable this setting only if the server is a trusted domain.

  • Delete the custom common names.
  • Import exclusions manually If you work in a closed environment or prefer to update default exclusions manually.
  • Refresh the COMMON NAME EXCLUSIONS/INCLUSIONS table to get the latest data.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden