To update the certificate for a protected internal server
without incurring downtime, follow these steps:
Installation of the new certificate doesn't impact
existing connections. The
NGFW verifies
that the certificate in the Server Hello message matches
the certificate in your decryption policy rule. If there
isn't a match, the session ends, and the corresponding
decryption log
entry reports the session-end reason as a certificate
mismatch between the firewall and server. To view the
server certificates used in all inbound inspection
sessions, select the
Log Successful TLS
handshakes and
Log
Unsuccessful TLS handshakes options
under the Log Settings section of a decryption policy
rule.