- CheckMates
- :
- Products
- :
- General Topics
- :
- fwmonitor on decrypted traffic
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
fwmonitor on decrypted traffic
CheckMates,
In order to troubleshoot, is there a way to fwmonitor traffic decrypted by HTTPS Inspection?
I am aware of the fact that it is only decrypted in the box: it will enter and leave the box encrypted. I am aware of the fact that it is bordering (malicious) MitM functionality, but it is sometimes essential to analysis.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
One of the features we added to R80.20 is "Mirror Decrypt and Forward."
This would allow you to look at decrypted traffic, but it would be sent out a specific interface.
So it is possible to see the traffic, but I don't think you can with fw monitor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ok, sounds like a useful option. Once you can send it to an interface, you can tcpdump it, I guess.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The use case for the feature is sending the unencrypted traffic to another system for analysis or archive.
And sure, you could probably tcpdump it also.
