SDWAN TLS/SSL Profile Policy

The TLS/SSL Profile policy is used to manage encrypted traffic within a unified security policy. To create a TLS/SSL Profile Policy in Security Cloud Control, you need to first configure the Certificate Authority (CA) Certificate in Catalyst SD-WAN. This is a prerequisite for enabling the TLS proxy functionality.

TLS/SSL Profile Policy

Field

Description

Object Name

Name of the TLS/SSL profile.

Categories to assign action

Set the categories between the actions—Decrypt, No Decrypt, and Pass Through URL Categories.

Alternatively, choose multiple categories and set the action.

Reputation

Enable reputation to choose the Decrypt Threshold.

Supports actions based on URL reputation levels.

Decrypt Domain List

Choose the decrypt domain list.

No Decrypt Domain List

Choose the no decrypt domain list.

Fail Decrypt

Enable the fail decrypt option, if decryption fails.