Enabling SSL Control on Zones

After SSL Control has been globally enabled, and the desired options have been configured, SSL Control must be enabled on one or more zones. When SSL Control is enabled on the zone, the firewall looks for Client Hellos sent from clients on that zone through the firewall will trigger inspection. The firewall then looks for the Server Hello and Certificate that is sent in response for evaluation against the configured policy. Enabling SSL Control on the LAN zone, for example, will inspect all SSL traffic initiated by clients on the LAN to any destination zone.

To enable SSL Control on a zone:
1
Navigate to the Network > Zones page.
2
Select the Configure icon for the desired zone. The Edit Zone dialog displays.
3
Select the Enable SSL Control checkbox.
4
Click OK. All new SSL connections initiated from that zone are now subject to inspection.