Decryption in Private Access Rules
Decryption is required for effective Intrusion prevention (IPS), file inspection, and file type blocking. Traffic must be decrypted in order to inspect it for known threats and behaviors.
Traffic to private resources will be decrypted only if decryption is enabled for that resource and the required certificate is present. Configure decryption for private resources when you configure the private resource.
Traffic to private destinations that are not configured as private resources (that is, traffic to destinations that you type directly into an access rule) is not decrypted.