Friday Firepower Hour - SSL Policy

preview_player
Показать описание
In this Friday Firepower Hour session, we cover how to configure an SSL Policy. We walk through on how to configure the Firepower Management Center as a Subordinate CA to your MS CA and then add this setting to a SSL Policy.
We then test using 2 computers of which, 1 is domain joined and the other as a standalone to see the end user experience.
Рекомендации по теме
Комментарии
Автор

very nice walk-through by Cisco experts. very relevant content with the large percentage of malware encrypting their traffic to avoid detection

DavidDaverso
Автор

Very informative, is the certificate generation and installation process different for public SSL certs? I see some guides using OpenSSL and not the FMC etc. or is the process the same so for instance when deploying SSL certs to be used in RA VPN? thank you

Bormanb
Автор

If you are going to allow a specific piece of a Web Application or category (, such as allowing google drive, but not gmail, or allowing facebook logins, but not all of facebook ) would you inspect the specific traffic (category or application) and resign it in the SSL policy and then allow it via your ACL? Thanks, loved the video!

daviddennis
Автор

Great presentation. What do we do in instances where you are hosting an external-facing website using a publicly signed SSL certificate (Entrust, Verisign, etc) on the load balancer or server? Can we decrypt that traffic? Or do SSL policies only work for internal PKI certs where the FMC can be a subordinate CA for? Thanks!

ccsmooth