11.21. SSL Forwarding Profiles

SSL forwarding profiles work together with SSL inspection rules and allow you to specify the devices to which a copy of the decrypted traffic should be forwarded. The copy will be sent in case of a successful decryption of the traffic according to the SSL inspection rule and selected SSL profile.

To create an SSL forwarding profile, go to the Libraries --> SSL forwarding profiles section, click Add, and provide the desired settings:

Name

Description

Name

The name of the SSL forwarding profile.

Description

A description of the SSL forwarding profile.

Forwarding type

The available forwarding types are:

  • L2: configured by specifying the device's MAC address and the name of the interface to which the copied traffic should be redirected.

  • L3 tunnel: a copy of the decrypted traffic is transmitted over a GRE tunnel. This option is configured by specifying the source and destination IP addresses for the GRE tunnel.

Destination MAC

The MAC address of the device to which a copy of the decrypted traffic should be redirected. Specified if L2 is selected as the forwarding type.

Forward to interface

The name of the interface to which a copy of the decrypted traffic should be forwarded. Specified if L2 is selected as the forwarding type.

GRE source IP

The source IP address for the GRE tunnel. Specified if L3 is selected as the forwarding type.

GRE destination IP

The destination IP address for the GRE tunnel. Specified if L3 is selected as the forwarding type.