When you need to change the certificate on a server for
which the firewall performs
SSL Inbound Inspection,
add the new certificate to
the Decryption policy rule for that server before you make the change
on the server. Decryption policy rules support multiple server certificates,
so you can keep the old certificate and also add the new certificate
to the rule. This avoids any interruption in decryption due to changing
the certificate on the server when the firewall only has the old
certificate. Adding the new server certificate to the Decryption
policy rule ensures that when you change the certificate on the
server, the firewall has the right certificate to continue decrypting
traffic seamlessly.