Chapter 37 SSL Inspection
ZyWALL / USG (ZLD) CLI Reference Guide
258
The following sections list the commands.
37.2.1 SSL Inspection Exclusion Commands
There may be privacy and legality issues regarding inspecting a user's encrypted session. The legal
issues may vary by locale, so it's important to check with your legal department to make sure that
it’s OK to intercept SSL traffic from your ZyWALL / USG users.
To ensure individual privacy and meet legal requirements, you can configure an exclusion list to
exclude matching sessions to destination servers. This traffic is not intercepted and is passed
through uninspected.
This table lists the SSL Inspection exclusion-related commands.
37.2.2 SSL Inspection Profile Settings
This table lists the SSL Inspection profile setting commands.
Table 148
SSL Inspection Exclusion Commands
COMMAND
DESCRIPTION
ssl-inspection exclude-list-
settings
Use these commands to create a log for traffic that bypasses SSL
Inspection.
[no] log
The
no
command disables SSL exclusion list logs.
ssl-inspection exclude-list
SSL traffic to a server to be excluded from SSL Inspection is identified
by its certificate.
[no] entry {IPv4 |
IPv4_CIDR | IPv4_RANGE |
IPv6 | IPv6_PREFIX |
IPv6_RANGE |
SSL_INSPECTION_WILDCARD_C
NAME}
Identify the certificate in one of the following ways:
•
Type an IPv4 or IPv6 address. For example, type 192.168.1.35, or
2001:7300:3500::1
•
Type an IPv4/IPv6 in CIDR notation. For example, type
192.168.1.1/24, or 2001:7300:3500::1/64
•
Type an IPv4/IPv6 address range. For example, type 192.168.1.1-
192.168.1.35, or 2001:7300:3500::1-2001:7300:3500::35
•
Type a DNS name or a common name (wildcard char: '*', escape
char: '\'). Use up to 127 case-insensitive characters (0-9a-zA-
Z`~!@#$%^&*()-_=+[]{}\|;:',.<>/?). ‘*’ can be used as a
wildcard to match any string. Use ‘\*’ to indicate a single wildcard
character.
•
Type an email address. For example, type [email protected]
The
no
command disables the SSL entry.
show ssl-inspection exclude-
list [settings]
Displays SSL exclusion list settings.
Table 149
SSL Inspection Profile Commands
COMMAND
DESCRIPTION
ssl-inspection profile
SSI_profile_name
Creates an SSL Inspection profile. Use 1-31 alphanumeric
characters, underscores(
_
), or dashes (-), but the first character
cannot be a number. This value is case-sensitive.
description description
Enter additional information about this SSL Inspection entry. You
can enter up to 60 characters ("0-9", "a-z", "A-Z", "-" and "_").
no description
Deletes the description in a profile.
certificate cert_name
Enter the default certificate or one already created for this profile.
no certificate
Removes the certificate from this profile.
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...