Configure security rules to protect AI traffic flowing through Managed AIRS for
AWS.
| Where Can I Use This? | What Do I Need? |
|
|
- Access to Strata Cloud Manager (SCM)
|
Prerequisites:
Ensure the structural configuration snippet includes the baseline default
AIRS best practices profile for proper classification.
Outbound SSL decryption rules must be explicitly configured alongside
matching decryption certificates. Since prompt data payloads are encrypted under
standard HTTPS traffic, a lack of decryption configuration prevents the firewall
from parsing payload contents, rendering threat inspection non-functional. The
application chatbot or container pod store must be configured to trust this root
certificate in its CA chain.
Following are the steps to secure and configure security rules to protect
AIT traffic on Managed AIRS for AWS: