Where permitted by law, you can decrypt traffic and send unencrypted traffic to a
device that can archive and analyze the traffic.
| Where Can I Use This? | What Do I Need? |
Before you configure
Decryption Port Mirroring, you must obtain a Decryption Port
Mirroring license for each Next-Generation Firewall (
NGFW) that will
forward decrypted traffic. The license is free of charge and does not expire.
Install each license on its respective
NGFW, and then complete the
configuration steps for your management platform.
Important Considerations
We recommend consulting corporate counsel before enabling this feature in a
production environment. Note the following:
Certain countries regulate how you decrypt, inspect, store, or otherwise use
SSL/TLS traffic. User consent might be required to mirror traffic.
Malicious users with administrative access to the NGFW could
potentially harvest sensitive information (such as usernames, passwords,
social security numbers, and credit card numbers) submitted through
encrypted channels.
Request a Decryption Port Mirroring license.
Select , and then locate the NGFW you want to
license.
In the Actions column for that NGFW,
select .
On the Licenses & Subscriptions page, select
Activate License.
For Activation Types, select Activate
Feature License.
For Activate Feature License, select
Decryption Port Mirror.
Review the legal notice, and then click Agree and
Submit.
The license is now active and displays in the Cloud Delivered Security
Services list.
(Optional) Repeat these steps for additional NGFWs.
Install the license on an NGFW.
Log in to the web interface.
Select .
In the License Management section, click Retrieve license keys
from license server.
Reboot the NGFW.
Select .
In the Device Operations section, click Reboot
Device.
Click Yes to confirm.
Verify that the license is active on the NGFW.