Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Marcel_Wildenbe
Contributor

fwmonitor on decrypted traffic

CheckMates,

In order to troubleshoot, is there a way to fwmonitor traffic decrypted by HTTPS Inspection?

I am aware of the fact that it is only decrypted in the box: it will enter and leave the box encrypted. I am aware of the fact that it is bordering (malicious) MitM functionality, but it is sometimes essential to analysis.

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

One of the features we added to R80.20 is "Mirror Decrypt and Forward."

This would allow you to look at decrypted traffic, but it would be sent out a specific interface.

So it is possible to see the traffic, but I don't think you can with fw monitor.

0 Kudos
Marcel_Wildenbe
Contributor

Ok, sounds like a useful option. Once you can send it to an interface, you can tcpdump it, I guess.

0 Kudos
PhoneBoy
Admin
Admin

The use case for the feature is sending the unencrypted traffic to another system for analysis or archive.

And sure, you could probably tcpdump it also.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events