cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post

fwmonitor on decrypted traffic

CheckMates,

In order to troubleshoot, is there a way to fwmonitor traffic decrypted by HTTPS Inspection?

I am aware of the fact that it is only decrypted in the box: it will enter and leave the box encrypted. I am aware of the fact that it is bordering (malicious) MitM functionality, but it is sometimes essential to analysis.

0 Kudos
3 Replies
Admin
Admin

Re: fwmonitor on decrypted traffic

One of the features we added to R80.20 is "Mirror Decrypt and Forward."

This would allow you to look at decrypted traffic, but it would be sent out a specific interface.

So it is possible to see the traffic, but I don't think you can with fw monitor.

0 Kudos
Highlighted

Re: fwmonitor on decrypted traffic

Ok, sounds like a useful option. Once you can send it to an interface, you can tcpdump it, I guess.

0 Kudos
Admin
Admin

Re: fwmonitor on decrypted traffic

The use case for the feature is sending the unencrypted traffic to another system for analysis or archive.

And sure, you could probably tcpdump it also.

0 Kudos