Zyxel USG 1900 [267/438] Ssl inspection

Zyxel USG 1900 [267/438] Ssl inspection
ZyWALL / USG (ZLD) CLI Reference Guide 267
CHAPTER 38
SSL Inspection
This chapter describes how to set up SSL Inspection for the ZyWALL / USG.
38.1 SSL Inspection Overview
Secure Socket Layer (SSL) traffic, such as https://www.google.com/HTTPS, FTPs, POP3s, SMTPs,
etc. is encrypted, and cannot be inspected using Unified Threat Management (UTM) profiles such as
App Patrol, Content Filter, Intrusion, Detection and Prevention (IDP), or Anti-Virus. The ZyWALL /
USG uses SSL Inspection to decrypt SSL traffic, sends it to the UTM engines for inspection, then
encrypts traffic that passes inspection and forwards it to the destination server, such as Google.
The ZyWALL / USG supports the following in SSL Inspection:
Supported Cipher Suite
RC4 (Rivest Cipher 4)
DES (Data Encryption Standard)
•3DES
AES (Advanced Encryption Standard)
SSLv3/TLS1.0 (Transport Layer Security) Support
SSLv3/TLS1.0 is currently supported with option to pass or block SSLv2 traffic
Traffic using TLS1.1 (Transport Layer Security) or TLS1.2 is downgraded to TLS1.0 for SSL
Inspection
No Compression Support at time of writing
No Client Authentication Request Support at time of writing
38.2 SSL Inspection Commands Summary
The following table describes the values required for many SSL inspection commands. Other values
are discussed with the corresponding commands.
Table 149 Input Values for SSL Inspection Commands
LABEL DESCRIPTION
ssi_profile_name This is the name of the profile. You may use 1-31 alphanumeric characters,
underscores(
_), or dashes (-), but the first character cannot be a number. This value is
case-sensitive.
description This is additional information about this SSL Inspection profile. You can enter up to 60
characters ("0-9", "a-z", "A-Z", "-" and "_").
cert_name This is a name of a certificate.

Содержание

Похожие устройства

Скачать