Zyxel ZyWALL 1100 [268/438] Ssl inspection exclusion commands

Zyxel ZyWALL 1100 [268/438] Ssl inspection exclusion commands
Chapter 38 SSL Inspection
ZyWALL / USG (ZLD) CLI Reference Guide
268
The following sections list the commands.
38.2.1 SSL Inspection Exclusion Commands
There may be privacy and legality issues regarding inspecting a user's encrypted session. The legal
issues may vary by locale, so it's important to check with your legal department to make sure that
it’s OK to intercept SSL traffic from your ZyWALL / USG users.
To ensure individual privacy and meet legal requirements, you can configure an exclusion list to
exclude matching sessions to destination servers. This traffic is not intercepted and is passed
through uninspected.
This table lists the SSL Inspection exclusion-related commands.
38.2.2 SSL Inspection Profile Settings
This table lists the SSL Inspection profile setting commands.
Table 150 SSL Inspection Exclusion Commands
COMMAND DESCRIPTION
ssl-inspection exclude-list-
settings
Use these commands to create a log for traffic that bypasses SSL
Inspection.
[no] log The no command disables SSL exclusion list logs.
ssl-inspection exclude-list SSL traffic to a server to be excluded from SSL Inspection is identified
by its certificate.
[no] entry {IPv4 |
IPv4_CIDR | IPv4_RANGE |
IPv6 | IPv6_PREFIX |
IPv6_RANGE |
SSL_INSPECTION_WILDCARD_C
NAME}
Identify the certificate in one of the following ways:
Type an IPv4 or IPv6 address. For example, type 192.168.1.35, or
2001:7300:3500::1
Type an IPv4/IPv6 in CIDR notation. For example, type
192.168.1.1/24, or 2001:7300:3500::1/64
Type an IPv4/IPv6 address range. For example, type 192.168.1.1-
192.168.1.35, or 2001:7300:3500::1-2001:7300:3500::35
Type a DNS name or a common name (wildcard char: '*', escape
char: '\'). Use up to 127 case-insensitive characters (0-9a-zA-
Z`~!@#$%^&*()-_=+[]{}\|;:',.<>/?). ‘*’ can be used as a
wildcard to match any string. Use ‘\*’ to indicate a single wildcard
character.
Type an email address. For example, type abc@zyxel.com.tw
The no command disables the SSL entry.
show ssl-inspection exclude-
list [settings]
Displays SSL exclusion list settings.
Table 151 SSL Inspection Profile Commands
COMMAND DESCRIPTION
ssl-inspection profile
SSI_profile_name
Creates an SSL Inspection profile. Use 1-31 alphanumeric
characters, underscores(
_), or dashes (-), but the first character
cannot be a number. This value is case-sensitive.
description description Enter additional information about this SSL Inspection entry. You
can enter up to 60 characters ("0-9", "a-z", "A-Z", "-" and "_").
no description Deletes the description in a profile.
certificate cert_name Enter the default certificate or one already created for this profile.
no certificate Removes the certificate from this profile.

Содержание

Похожие устройства