SonicOS 7.0 DPI-SSL

Configuring Server-to-Certificate Pairings

Server DPI-SSL inspection requires that you specify which certificate is used to sign traffic for each server that has DPI-SSL inspection performed on its traffic.

To configure a server-to-certificate pairing

  1. Navigate to the POLICY | DPI-SSL > Server SSL page.
  2. Scroll to the SSL Servers section.

  3. Click +Add. The Server DPI-SSL - SSL Server Setting dialog displays.

  4. From Address Object/Group, select the address object or group for the server or servers to which you want to apply DPI-SSL inspection.

  5. From SSL Certificate, select the certificate to be used to sign the traffic for the server. This certificate is used to sign traffic for each server that has DPI-SSL Server inspection performed on its traffic. For more information on:

  1. Select Cleartext to enable SSL offloading. When adding server-to-certificate pairs, the Cleartext option provides a method of sending unencrypted data onto a server. This option is not selected by default.

    For such a configuration to work properly, a NAT policy needs to be created for this server on the POLICY | Rules and Policies > NAT Rules page to map traffic destined for the offload server from an SSL port to a non-SSL port. Traffic must be sent over a port other than 443. For example, for HTTPS traffic used with SSL offloading, an inbound NAT policy remapping traffic from port 443 to port 80 needs to be created for things to work properly.

  2. Click Add.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden