ducthxnh
Intern
IV.4 Cấu hình tính năng SSL Decryption để giải mã traffic
Cấu hình tính năng SSL Decryption để giải mã các traffic được mã hóa để nhằm kiểm tra sau vào dữ liệu khi đi qua NGFW (bao gồm Outbound Inspection traffic từ bên trong đi Internet và Inbound Inspection traffic từ bên ngoài vào server nội bộ)1 — OUTBOUND INSPECTION (Inside/DMZ ra Internet)
1.1 Tạo CA riêng cho Forward Proxy
Device > Certificate Management > Certificates > Generate
Certificate Name Forward-Trust-CA
Common Name Forward-Trust-CA
Certificate Authority ✔ tick
Algorithm RSA, 2048
Sau khi Generate xong, tìm lại cert này trong danh sách → mở lại (click vào tên) → tick thêm: Forward Trust Certificate
1.2. Export CA để cài cho client
Tick chọn Forward-Trust-CA → Export Certificate
**Tới đây nên up cert lên trước (gg drive, github, …..), xong lấy máy vlan lên link tải về trước khi cấu hình yêu cầu chứng chỉ
1.3. Tạo Decryption Profile
Objects > Decryption > Decryption Profile > Add
Name SSL-Decrypt-Profile
Tab SSL Forward Proxy Giữ mặc định, có thể tick thêm Block sessions with expired certificate, Block sessions with untrusted issuer để chặt chẽ hơn
1.4 Tạo Decryption Policy (Outbound)
Policies > Decryption > Add
Name Decrypt-Outbound
Source Zone Inside-VLAN10, Inside-VLAN20 (thêm DMZ nếu muốn)
Destination Zone Outside
Service/URL Category any
Tab Options — Action Decrypt
Type SSL Forward Proxy
Decryption Profile SSL-Decrypt-Profile
Tab Options — Log Successful SSL Handshake ✔ (để xem log kiểm chứng)
OK → Commit.
Kiểm thử
Máy vlan không truy cập được Internet
Cài cert
Truy cập lại bình thường
Đính kèm
Bài viết liên quan
Được quan tâm
Bài viết mới