Select from predefined URL categories or
Create
New custom URL categories. The
NGFW
excludes traffic to selected categories from decryption unless you
create an exception rule.
You can also Add External Dynamic Lists or
Add SaaS Application Endpoints.
Specify that you don't want to decrypt traffic matching the rule.
In the Action and Advanced Inspection section, for
Action, select Do Not
Decrypt.
(
Best Practice) Apply a decryption profile that blocks sessions with
expired certificates and untrusted issuers.
Configure or modify a no-decryption profile
if you haven't already.
Select the No Decryption tab.
For Server Certificate
Verification, select Block
sessions with expired certificate and
Block sessions with untrusted
issuer.
- Save the profile.
- In the Action and Advanced Inspection section, select the no-decrypt
Decryption Profile.
Save the rule.
Move (or drag and drop) the decryption exclusion rule to
the top of the rulebase.
The NGFW enforces decryption rules against incoming traffic in
the rulebase sequence and enforces the first rule that matches the
traffic.