Describes Manage Traffic Decryption in Cisco Secure Access and explains Decryption Requires Certificates, Decryption Logging, and Troubleshooting Decryption. It summarizes the behavior, configuration context, and operational considerations presented throughout the topic.
Decryption is used for various purposes in Secure Access. You can configure decryption on these components:
-
Security Profiles—For more information, see Security profiles for Internet Access.
-
Do Not Decrypt List—For more information, see Add a Do Not Decrypt List for Security Profiles and Internet Access.
-
Private Resources—For more information, see Add a Private Resource.
-
Global Settings— Several settings affect decryption for private or internet traffic or both. For more information, see Global Settings.
Decryption Requires Certificates
In most cases, decryption requires that you upload or install certificates. Intrusion Prevention (IPS) requires decryption in order to effectively evaluate threats in traffic.
For internet traffic, see Certificates for Internet Decryption.
For private resource destinations, see Manage Certificates for Private Resource Decryption.
Decryption Logging
You can enable or disable decryption logging in the Global Settings of the Access policy. For more information, see Edit Rule Defaults and Global Settings.
To view your decryption logs, see Reports.
Troubleshooting Decryption
If you suspect decryption is causing issues, check your decryption logs or temporarily disable decryption globally on the Global Settings page for the specified features. For more information, see Global Settings for Access Rules and Edit Rule Defaults and Global Settings.
Your issue may not be specifically related to decryption. For example, see Troubleshoot Private Access Rules and Troubleshoot Internet Access Rules.