Decryption profiles enable you to block and control
specific aspects of SSL and SSH traffic that you have specified
for decryption, as well as traffic that you have explicitly excluded
from decryption. After you create a decryption profile, you can
then add that profile to a decryption policy; any traffic matched
to the decryption policy is additionally enforced based on the profile
settings.
A default decryption profile is configured on the firewall, and
is automatically included in new decryption policies (you cannot
modify the default decryption profile). Click Add to
create a new decryption profile, or select an existing profile to Clone or
modify it.