Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage Traffic Decryption

Want to summarize with AI?

Log in

Describes Manage Traffic Decryption in Cisco Secure Access and explains Decryption Requires Certificates, Decryption Logging, and Troubleshooting Decryption. It summarizes the behavior, configuration context, and operational considerations presented throughout the topic.


Decryption is used for various purposes in Secure Access. You can configure decryption on these components:

Decryption Requires Certificates

In most cases, decryption requires that you upload or install certificates. Intrusion Prevention (IPS) requires decryption in order to effectively evaluate threats in traffic.

For internet traffic, see Certificates for Internet Decryption.

For private resource destinations, see Manage Certificates for Private Resource Decryption.

Decryption Logging

You can enable or disable decryption logging in the Global Settings of the Access policy. For more information, see Edit Rule Defaults and Global Settings.

To view your decryption logs, see Reports.

Troubleshooting Decryption

If you suspect decryption is causing issues, check your decryption logs or temporarily disable decryption globally on the Global Settings page for the specified features. For more information, see Global Settings for Access Rules and Edit Rule Defaults and Global Settings.

Your issue may not be specifically related to decryption. For example, see Troubleshoot Private Access Rules and Troubleshoot Internet Access Rules.


Internet Access Features That Require Decryption

The following features require decryption or do not work effectively on encrypted traffic:

  • Intrusion prevention (IPS) for traffic to internet destinations.

    Traffic must be decrypted to inspect HTTPS traffic for known threats and behaviors.

  • Security features configured in security profiles.

    Decryption is required for inspection by the security and acceptable use features. The security profile specified in any internet access rule should have decryption enabled, unless the destinations are trusted.

  • Remote browser isolation (RBI).

    If you choose Isolate as the rule action in an internet access rule, affected traffic must be decrypted. Enable decryption in the security profile that you choose for that rule.

Sites that use HTTP rather than HTTPS do not require decryption to benefit from the functionality listed above. However, most sites use HTTPS. Enforcement based on threat categories never requires decryption.


Internet Traffic That Should Not Be Decrypted

Traffic that should not be decrypted How to Configure, and More Information
Traffic to confidential internet destinations, based on laws, regulations, or policy See Important Information About Do Not Decrypt Lists.
Sites with pinned certificates (for IPS) See Global Settings for Access Rules.
Sites with pinned certificates (for other features) N/A
Microsoft 365 applications See Global Settings for Access Rules.
Trusted files
Traffic from certain sources, such as printers or IoT devices, on which certificates cannot be installed See the Disable Decryption for Specific Sources section in Global Settings for Access Rules.

Decryption in Private Access Rules

Decryption is required for effective Intrusion prevention (IPS), file inspection, and file type blocking. Traffic must be decrypted in order to inspect it for known threats and behaviors.

Traffic to private resources will be decrypted only if decryption is enabled for that resource and the required certificate is present. Configure decryption for private resources when you configure the private resource. For more information, see Add a Private Resource.

Note

If you enter the configuration of the private destinations directly on the private access rules, traffic to these private destinations is not decrypted.


Important Information About Do Not Decrypt Lists

Traffic that is not decrypted cannot be effectively inspected for threats.

However, in order to comply with confidentiality regulations in some locations, certain traffic should not be decrypted. You can use Do Not Decrypt lists to specify these destinations.

Do Not Decrypt lists apply only to destinations in internet access rules, and they are used for intrusion prevention (IPS) and for features configured in security profiles.

Currently, IPS profiles and security profiles support Do Not Decrypt lists differently:

  • All IPS profiles use a single Do Not Decrypt list.
  • Each security profile for internet access can use any Do Not Decrypt list.
  • The types of destinations that you can specify for IPS and for a security profile are different. See the applicable sections below.

Do Not Decrypt List for IPS

Destinations on the system-provided Do Not Decrypt list are not decrypted for inspection by the intrusion prevention (IPS) feature.

All IPS profiles use the system-provided Do Not Decrypt list that ships with Secure Access. You can add destinations to this list.

To configure this list, navigate to Secure > Settings > Do Not Decrypt Lists.

Note
Do not use the system-provided Do Not Decrypt list for private destinations. Instead, you can configure a private resource and not enable decryption for that resource. See Add Private Resources.

Do Not Decrypt Lists for Security Profiles for Internet Access

When a Do Not Decrypt list is associated with a security profile for internet access, destinations on the list will not be decrypted by the security and acceptable use features enabled in that profile.

Initially, the default Do Not Decrypt List for security profiles is the same system-provided Do Not Decrypt List that is used for IPS. You can either use this single list for both IPS and security profiles for internet access, or you can create additional do-not-decrypt lists for use in security profiles for internet access. See Add a Do Not Decrypt List for Security Profiles for Internet Access.

Differences Between IPS and Features in Security Profiles

The types of destinations that you can choose not to decrypt is different for IPS and features configured in security profiles for internet access:

Applications Sites that belong to specified Content Categories Domains
IPS No Yes Yes
Features in Security Profiles Yes Yes Yes

The System-Provided Do Not Decrypt List

The system-provided Do Not Decrypt list is the only list used by the IPS feature. The same list is the default list used by the features in the security profile for internet access. The system-provided Do Not Decrypt list does not include the ability to specify applications; this option is available only in custom lists.

Initially, this list is empty. Add the destinations that are important to your organization.

Limitation: Do Not Decrypt Based on Content Category

While web site categorization is updated continuously, it is not possible to categorize all web sites on the internet, and some sites may be categorized incorrectly. Therefore, if you choose not to decrypt traffic based on content category, it is possible that traffic to sites that should not be decrypted may be decrypted, and traffic that should be decrypted may not be decrypted.

This limitation is not unique to Cisco.


Add a Do Not Decrypt List for Security Profiles and Internet Access

In order to comply with the local confidentiality you can exclude specific traffic from decryption.

Create a custom Do Not Decrypt list to specify destinations that will not be decrypted by the security and acceptable use features configured in a security profile for internet access. HTTPS traffic to these destinations cannot be properly inspected for threats when traffic is not decrypted.

If you need to specify a Do Not Decrypt address for IPS profiles, edit the system-provided Do Not Decrypt List.

Note
To exclude all applications that use Google APIs from decryption, select Google APIs from the application list and add the domain googleapis.com to the list of domains.

Before you begin

Procedure

  1. Navigate to Secure > Settings > Do Not Decrypt Lists and click + Add List.

    Do Not Decrypt Lists page with an option to add a new list
  2. Enter a descriptive name for your list in the List Name field.

    Security Profile Only section with option for configuring the parameters for the list
  3. Add content categories, applications, and domains that will be exempt from decryption.

    1. Under Content Categories, check one or more Content Categories checkbox to exempt from HTTPS inspection, then click Save.
      Security Profile Only section with options to select categories to exempt from HTTPS inspection
    2. Under Domains, to add multiple domains manually, click the Manual radio button, enter the doamin, then click Add to exempt domain from HTTPS inspection, and then click Save. Optionally, to upload multiple domains and hosts in bulk, click the Bulk radio button, upload the list in a .csv or .txt file, and then click Save.
      Security Profile Only section with an option to add domains to exempt from HTTPS inspection
    3. Under IP/CIDR, to add multiple IP addresses and CIDRs manually, click the Manual radio button, enter the IP addess and CIDR, then click Add to exempt IP addresses and CIDRs from HTTPS inspection, and then click Save. Optionally, to upload multiple IP addresses and CIDRs in bulk, click the Bulk radio button, upload the list in a .csv or .txt file, and then click Save.
    4. Under Applications, check one or more Applications checkbox to exempt from HTTPS inspection, and then click Save.
      Security Profile Only section with an option to add applications to exempt from decryption
      Note
      When you create a new list, add entries manually one at a time. After you save the list, the Bulk add domain option becomes available for the Domain and IP/CIDR sections. You can add a combined total of two thousand destinations per list globally across all sections.

      After you add your custom Do Not Decrypt List, you can select the Do Not Decrypt List in a security profile for internet access.

  4. Click Save.

    After you add your custom Do Not Decrypt List, you can select the Do Not Decrypt List in a security profile for internet access.