You can
configure SSL Forward Proxy to decrypt and inspect SSL/TLS
traffic from internal users to the internet. SSL Forward Proxy decryption prevents
malware concealed as SSL encrypted traffic from being introduced into your corporate
network. When you enable SSL Forward Proxy, an
NGFW acts as a
forward proxy. It creates two separate sessions: one between the client and
the
NGFW, and the other between the
NGFW and the server.
The
NGFW uses
certificates to transparently
represent the client to the server and the server to the client, establishing itself as
a trusted third party or meddler in the middle. As a result, the client believes it's
communicating directly with the server, and the server believes it's communicating
directly with the client. All web traffic goes through the
NGFW, which
applies decryption profiles and Security policy rules and profiles to the traffic.
The following figure shows this process in detail.