Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

Decrypting SSL and TLS Traffic in Network Insights

date_range 11-Jul-22

SUMMARY To find hidden threats, it might be necessary to decrypt SSL and TLS traffic that is processed by JSA.

For Network Insights deployments, it is recommended that you use a dedicated man-in-the-middle solution where the clear text output is fed into JSA.

If you do not want to deploy a man-in-the-middle solution, limited decryption capabilities are available within JSA if the required keys are available. You will experience performance degradation if you enable the decryption capability.

Decryption is supported for the following protocols:
  • SSL v3
  • TLS v1.0
  • TLS v1.1
  • TLS v1.2
Restriction:

The Diffie Hellman key exchange mechanism is not supported when encrypted traffic is decrypted through a private key. When you use a private key, other key exchange methods, such as RSA, are supported.

footer-navigation