Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Marcel_Wildenbe
Contributor

fwmonitor on decrypted traffic

CheckMates,

In order to troubleshoot, is there a way to fwmonitor traffic decrypted by HTTPS Inspection?

I am aware of the fact that it is only decrypted in the box: it will enter and leave the box encrypted. I am aware of the fact that it is bordering (malicious) MitM functionality, but it is sometimes essential to analysis.

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

One of the features we added to R80.20 is "Mirror Decrypt and Forward."

This would allow you to look at decrypted traffic, but it would be sent out a specific interface.

So it is possible to see the traffic, but I don't think you can with fw monitor.

0 Kudos
Marcel_Wildenbe
Contributor

Ok, sounds like a useful option. Once you can send it to an interface, you can tcpdump it, I guess.

0 Kudos
PhoneBoy
Admin
Admin

The use case for the feature is sending the unencrypted traffic to another system for analysis or archive.

And sure, you could probably tcpdump it also.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 07 May 2026 @ 01:30 PM (AEST)

    CheckMates Live Sydney

    Tue 02 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Aarhus

    Wed 03 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Copenhagen
    CheckMates Events