Chapter 37 SSL Inspection
ZyWALL / USG (ZLD) CLI Reference Guide
259
37.2.3 SSL Inspection Certificate Cache
This table lists the SSL Inspection certificate cache commands.
37.2.4 SSL Inspection Certificate Update
Use these commands to update the latest certificates of servers using SSL connections to the
ZyWALL / USG network. You should have Internet access and have activated SSL Inspection on the
ZyWALL / USG at myZyXEL.com.
This table lists the SSL Inspection certificate cache commands.
follow-real-client-routing
{yes | no}
When a new SSL session is found by SSL inspection, it will create
another independent session from the ZyWALL / USG to get
information such as the certificate chain. However, since this
traffic is sent from the ZyWALL / USG, it may not match the same
routing policy of the original SSL session and may not reach the
destination server.
Enable this command to allow the session sent from the ZyWALL /
USG to follow the routing policy of the original session. The
no
command does not allow the session sent from the ZyWALL / USG
to follow the routing policy of the original session.
sslv2 action {pass | block}
{no log | log [alert]}
SSL Inspection supports SSLv3 and TLS1.0. This command sets
the action and log for SSLv2 traffic.
unsupported-suite action {pass
| block} {no log | log [alert]}
Sets the action and log for unsupported suite traffic.
untrusted-cert-chain action
{pass | block} {no log | log
[alert]}
As a SSL session is being established, servers send their
certificate chain to clients. The ZyWALL / USG trusts its own
certificates and imported (trusted) certificates to verify the
certificate chain. This command sets the action and log for traffic
from a server with an untrusted certificate chain.
ssl-inspection profile rename
ssi_profile_name1 ssi_profile_name2
Renames an SSL Inspection profile.
no ssl-inspection profile
ssi_profile_name
Deletes an SSL Inspection profile.
show ssl-inspection profile
[
ssi_profile_name
]
Displays SSL Inspection profile settings.
Table 149
SSL Inspection Profile Commands
COMMAND
DESCRIPTION
Table 150
SSL Inspection Certificate Cache Commands
COMMAND
DESCRIPTION
ssl-inspection cache flush
Clears SSL Inspection cached entries.
show ssl-inspection cert-list
Displays certificates used in SSL Inspection.
Table 151
SSL Inspection Certificate Update Commands
COMMAND
DESCRIPTION
[no] ssl-inspection cert-update
auto
ZyWALL / USG automatically updates the certificate set when a new
one becomes available on myZyXEL.com.
ssl-inspection cert-update now
Download the latest certificate set from the myZyXEL.com and
updates it on the ZyWALL / USG.
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...